Skip to main content

Adobe Monthly Security Update (Oct 2019)

Last Update Date: 13 Nov 2019 Release Date: 16 Oct 2019 4886 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe Experience ManagerMedium Risk Medium RiskInformation Disclosure
Elevation of Privilege
Remote Code Execution
 APSB19-48
Adobe AcrobatHigh Risk High RiskInformation Disclosure
Remote Code Execution
 [Updated 13-Nov-2019]: We noticed a Proof-of-Concept exploit software for CVE-2019-8195 and CVE-2019-8196 was developed and available for download. As such, the risk level was changed from Medium to High. APSB19-49
Adobe ReaderHigh Risk High RiskInformation Disclosure
Remote Code Execution
 [Updated 13-Nov-2019]: We noticed a Proof-of-Concept exploit software for CVE-2019-8195 and CVE-2019-8196 developed and available for download. As such, the risk level was changed from Medium to High.APSB19-49
Adobe Experience Manager FormsMedium Risk Medium RiskInformation Disclosure APSB19-50

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 2

Number of 'Medium Risk' product(s): 2

Evaluation of overall 'Risk Level': High Risk


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Adobe Experience Manager Version 6.0-6.5
  • Adobe Acrobat DC Version 2019.012.20040 and earlier
  • Adobe Reader DC Version 2019.012.20040 and earlier
  • Adobe Acrobat 2017 Version 2017.011.30148 and earlier
  • Adobe Reader 2017 Version 2017.011.30148 and earlier
  • Adobe Acrobat 2015 Version 2015.006.30503 and earlier
  • Adobe Reader 2015 Version 2015.006.30503 and earlier
  • Adobe Experience Manager Forms Version 6.3-6.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link