Data
Events
Data: CASIE
Negative Trigger
This
week
,
Adobe
released
Vulnerability-related.PatchVulnerability
its
monthly
scheduled
update
bundle
addressing
Vulnerability-related.PatchVulnerability
vulnerabilities
within
its
different
products
.
The
Adobe
patch
Tuesday
November
updates
allegedly
fixed
Vulnerability-related.PatchVulnerability
numerous
vulnerabilities
leading
to
information
disclosure
.
These
vulnerabilities
existed in
Vulnerability-related.DiscoverVulnerability
Adobe
Acrobat/Reader
,
Flash
Player
,
and
Photoshop
CC
.
The
recently
released
Adobe
Patch
Tuesday
November
updates
addressed
Vulnerability-related.PatchVulnerability
three
different
vulnerabilities
–
all
resulting
in
information
disclosure
.
The
first
one
existed in
Vulnerability-related.DiscoverVulnerability
the
Adobe
Photoshop
CC
affecting
Vulnerability-related.DiscoverVulnerability
versions
19.1.6
and
prior
for
both
Windows
and
MacOS
.
As
described
in
the
security
advisory
,
Adobe
has fixed
Vulnerability-related.PatchVulnerability
this
important
Out-of-bounds
read
vulnerability
(
CVE-2018-15980
)
in
the
Photoshop
CC
versions
19.1.7
and
20.0
.
The
second
information
disclosure
flaw
affected
Vulnerability-related.DiscoverVulnerability
Adobe
Reader
and
Acrobat
for
Windows
.
Explaining
about
the
flaw
in
their
advisory
,
Adobe
stated
,
“
Successful
exploitation
could
lead
to
an
inadvertent
leak
of
the
user
’
s
hashed
NTLM
password.
”
The
vulnerability
initially
received the CVE
Vulnerability-related.DiscoverVulnerability
number
CVE-2018-4993
,
when
Check
Point
Research
first reported
Vulnerability-related.DiscoverVulnerability
the
bug
.
However
,
as
recently disclosed
Vulnerability-related.DiscoverVulnerability
by
the
EdgeSpot
,
Adobe
only
patched
Vulnerability-related.PatchVulnerability
a
single
variant
of
this
bug
.
Whereas
,
the
EdgeSpot
team
discovered
Vulnerability-related.DiscoverVulnerability
other
variants
that
hinted
towards
a failed patching
Vulnerability-related.PatchVulnerability
of
the
bug
instead
of
a
new
vulnerability
.
The
patched
vulnerability
has now received CVE
Vulnerability-related.DiscoverVulnerability
number
CVE-2018-15979
“
to
reflect
that
the
patch
is available
Vulnerability-related.PatchVulnerability
”
.
The
third
vulnerability
addressed
Vulnerability-related.PatchVulnerability
this
month
is
an
out-of-bounds
Read
vulnerability
(
CVE-2018-15978
)
in
the
Adobe
Flash
Player
.
The
affected
versions
include
31.0.0.122
and
earlier
for
Windows
,
Linux
,
and
MacOS
.
Unlike
previous
months
,
the
Adobe
Patch
Tuesday
November
update
bundle
addressed
Vulnerability-related.PatchVulnerability
fewer
bugs
.
Moreover
,
none
of
the
patched
vulnerabilities
had
a
critical
severity
impact
.
In
October
,
Adobe
patched
Vulnerability-related.PatchVulnerability
86
different
vulnerabilities
including
47
critical
ones
.
Whereas
,
in
September
,
they
addressed
Vulnerability-related.PatchVulnerability
6
critical
flaws
.
Adobe
has fixed
Vulnerability-related.PatchVulnerability
the
bugs
CVE-2018-15980
and
CVE-2018-15978
in
Adobe
Photoshop
CC
versions
19.1.7
and
20.0
and
Adobe
Flash
Player
version
31.0.0.148
,
respectively
.
Whereas
,
CVE-2018-15979
has received
Vulnerability-related.PatchVulnerability
a
patch
in
Adobe
Acrobat
DC
and
Reader
DC
version
2019.008.20081
,
Acrobat
2017
and
Acrobat
Reader
DC
2017
version
2017.011.30106
,
and
Acrobat
DC
and
Acrobat
Reader
DC
(
Classic
2015
)
version
2015.006.30457
.
For
protection
against
the
three
important
vulnerabilities
addressed
Vulnerability-related.PatchVulnerability
in
November
updates
,
users
should
make
sure
to
upgrade
Vulnerability-related.PatchVulnerability
their
software
to
the
patched
versions
at
the
earliest
convenience
.
MWR
Labs
researchers
recently disclosed
Vulnerability-related.DiscoverVulnerability
two
high-security
vulnerabilities
in
LG
G3
,
G4
,
and
G5
mobile
devices
.
The
bugs
include
a
Path
Transversal
flaw
and
an
Arbitrary
File
Disclosure
flaw
,
according
to
the
respective
security
advisories
.
The
Path
Transversal
flaw
was
caused
by
the
application
not
validating
that
URL
parameters
did
not
contain
potentially
malicious
characters
and
could
allow
an
attacker
on
the
same
network
as
a
user
to
make
any
media
file
or
folder
shareable
without
authentication
or
user
interaction
.
The
Arbitrary
File
Disclosure
flaw
was
caused
by
the
SmartShare.Cloud
application
launching
an
unauthenticated
HTTP
Server
listening
on
all
interfaces
while
connected
to
a
WiFi
network
and
could
allow
an
attacker
to
retrieve
any
media
file
from
the
Cloud
storage
of
the
victim
as
long
as
they
knew
the
file
name
.
Users
are
encouraged
to
ensure
their
devices
are updated
Vulnerability-related.PatchVulnerability
to
the
latest
versions
as
Version
2.4.0
has
mitigated
Vulnerability-related.PatchVulnerability
the
issues