Security News > 2020 > December > Adobe Patches Code Execution Flaws in Prelude, Experience Manager, Lightroom

Adobe Patches Code Execution Flaws in Prelude, Experience Manager, Lightroom
2020-12-08 16:02

Adobe on Tuesday announced that security updates for its Prelude, Experience Manager and Lightroom products patch critical arbitrary code execution vulnerabilities.

In the Windows and macOS versions of the Prelude video logging and ingest tool, Adobe fixed a critical uncontrolled search path issue that can lead to arbitrary code execution in the context of the targeted user.

The same researcher also informed Adobe of a similar uncontrolled search path flaw affecting the Windows and macOS versions of the photo editing and organizing software Lightroom.

In its Experience Manager marketing product, Adobe fixed two vulnerabilities: an important-severity blind server-side request forgery bug that can lead to the disclosure of sensitive data, and a critical stored cross-site scripting issue that can lead to JavaScript code execution in the browser.

The software giant has also informed customers that it has updated over a dozen Experience Manager dependencies to patch various types of vulnerabilities, including resource consumption, SSRF, XXE injection, improper authorization, code execution, and directory traversal issues.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/LJkJ0PSNR7M/adobe-patches-code-execution-flaws-prelude-experience-manager-lightroom

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Adobe 105 47 824 1650 622 3143