Data: CASIE
Negative Trigger
its
monthly
scheduled
update
bundle
addressing
Vulnerability-related.PatchVulnerability
vulnerabilities
within
its
different
products
.
The
Adobe
patch
Tuesday
November
updates
allegedly
fixed
Vulnerability-related.PatchVulnerability
numerous
vulnerabilities
leading
to
information
disclosure
.
These
vulnerabilities
existed in
Vulnerability-related.DiscoverVulnerability
Adobe
Acrobat/Reader
,
Flash
Player
,
and
Photoshop
CC
.
The
recently
released
Adobe
Patch
Tuesday
November
updates
addressed
Vulnerability-related.PatchVulnerability
three
different
vulnerabilities
–
all
resulting
in
information
disclosure
.
The
first
one
existed in
Vulnerability-related.DiscoverVulnerability
the
Adobe
Photoshop
CC
affecting
Vulnerability-related.DiscoverVulnerability
versions
19.1.6
and
prior
for
both
Windows
and
MacOS
.
As
described
in
the
security
advisory
,
Adobe
has fixed
Vulnerability-related.PatchVulnerability
this
important
Out-of-bounds
read
vulnerability
(
CVE-2018-15980
)
in
the
Photoshop
CC
versions
19.1.7
and
20.0
.
The
second
information
disclosure
flaw
affected
Vulnerability-related.DiscoverVulnerability
Adobe
Reader
and
Acrobat
for
Windows
.
Explaining
about
the
flaw
in
their
advisory
,
Adobe
stated
,
“
Successful
exploitation
could
lead
to
an
inadvertent
leak
of
the
user
’
s
hashed
NTLM
password.
”
The
vulnerability
initially
received the CVE
Vulnerability-related.DiscoverVulnerability
number
CVE-2018-4993
,
when
Check
Point
Research
first reported
Vulnerability-related.DiscoverVulnerability
the
bug
.
However
,
as
recently disclosed
Vulnerability-related.DiscoverVulnerability
by
the
EdgeSpot
,
Adobe
only
patched
Vulnerability-related.PatchVulnerability
a
single
variant
of
this
bug
.
Whereas
,
the
EdgeSpot
team
discovered
Vulnerability-related.DiscoverVulnerability
other
variants
that
hinted
towards
a failed patching
Vulnerability-related.PatchVulnerability
of
the
bug
instead
of
a
new
vulnerability
.
The
patched
vulnerability
has now received CVE
Vulnerability-related.DiscoverVulnerability
number
CVE-2018-15979
“
to
reflect
that
the
patch
is available
Vulnerability-related.PatchVulnerability
”
.
The
third
vulnerability
addressed
Vulnerability-related.PatchVulnerability
this
month
is
an
out-of-bounds
Read
vulnerability
(
CVE-2018-15978
)
in
the
Adobe
Flash
Player
.
The
affected
versions
include
31.0.0.122
and
earlier
for
Windows
,
Linux
,
and
MacOS
.
Unlike
previous
months
,
the
Adobe
Patch
Tuesday
November
update
bundle
addressed
Vulnerability-related.PatchVulnerability
fewer
bugs
.
Moreover
,
none
of
the
patched
vulnerabilities
had
a
critical
severity
impact
.
In
October
,
Adobe
patched
Vulnerability-related.PatchVulnerability
86
different
vulnerabilities
including
47
critical
ones
.
Whereas
,
in
September
,
they
addressed
Vulnerability-related.PatchVulnerability
6
critical
flaws
.
Adobe
has fixed
Vulnerability-related.PatchVulnerability
the
bugs
CVE-2018-15980
and
CVE-2018-15978
in
Adobe
Photoshop
CC
versions
19.1.7
and
20.0
and
Adobe
Flash
Player
version
31.0.0.148
,
respectively
.
Whereas
,
CVE-2018-15979
has received
Vulnerability-related.PatchVulnerability
a
patch
in
Adobe
Acrobat
DC
and
Reader
DC
version
2019.008.20081
,
Acrobat
2017
and
Acrobat
Reader
DC
2017
version
2017.011.30106
,
and
Acrobat
DC
and
Acrobat
Reader
DC
(
Classic
2015
)
version
2015.006.30457
.
For
protection
against
the
three
important
vulnerabilities
addressed
Vulnerability-related.PatchVulnerability
in
November
updates
,
users
should
make
sure
to
upgrade
Vulnerability-related.PatchVulnerability
their
software
to
the
patched
versions
at
the
earliest
convenience
.