Skip to main content

Adobe Monthly Security Update (Dec 2016)

Last Update Date: 14 Dec 2016 10:57 Release Date: 14 Dec 2016 3569 Views

RISK: Extremely High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductSeverityImpactsNotesDetails (including CVE)
Flash PlayerExtremely Critical Extremely CriticalRemote Code Execution
Security Restriction Bypass
Exploits in the wildAPSB16-39
AnimateModerately Critical Moderately CriticalRemote Code ExecutionAPSB16-38
Experience Manager FormsModerately Critical Moderately CriticalCross-site ScriptingAPSB16-40
DNG ConverterModerately Critical Moderately CriticalRemote Code ExecutionAPSB16-41
Experience ManagerModerately Critical Moderately CriticalCross-site ScriptingAPSB16-42
InDesignModerately Critical Moderately CriticalRemote Code ExecutionAPSB16-43
ColdFusion BuilderModerately Critical Moderately CriticalInformation DisclosureAPSB16-44
Digital EditionsModerately Critical Moderately CriticalInformation DisclosureAPSB16-45
RoboHelpModerately Critical Moderately CriticalCross-site ScriptingAPSB16-46

 

Note for Adobe Flash Player:

An exploit for CVE-2016-7892 exists in the wild, and is being used in limited, targeted attacks against users running Internet Explorer (32-bit) on Windows.

 

Number of 'Extremely Critical' product(s): 1

Number of 'Highly Critical' product(s): 0

Number of 'Moderately Critical' product(s): 8

Evaluation of overall 'Criticality Level': Extremely Critical


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Adobe Animate 15.2.1.95 and earlier versions
  • Adobe Flash Player 23.0.0.207 and earlier
  • Adobe Flash Player for Google Chrome 23.0.0.207 and earlier
  • Adobe Flash Player for Microsoft Edge and Internet Explorer 11 23.0.0.207 and earlier
  • Adobe Flash Player for Linux 11.2.202.644 and earlier
  • Adobe Experience Manager Forms 6.0, 6.1, 6.2
  • Adobe LiveCycle 10.0.4, 11.0.1
  • Adobe DNG Converter 9.7 and earlier versions
  • Adobe Experience Manager 6.0, 6.1, 6.2
  • Adobe InDesign 11.4.1 and earlier versions
  • Adobe InDesign Server 11.0.0 and earlier versions
  • Adobe ColdFusion Builder 2016 Update 2 and earlier versions
  • Adobe ColdFusion Builder 3.0.3 and earlier versions
  • Adobe Digital Editions 4.5.2 and earlier versions
  • Adobe RoboHelp 2015.0.3 and earlier versions
  • Adobe RoboHelp 11 and earlier versions

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued security updates for the products. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link