Adobe Updates
2795Warning Date
Severity Level
Warning Number
Target Sector
9 December, 2020
● Critical
2020-2162
All
Description:
Adobe has released security updates to address several vulnerabilities in the following products:
- Adobe Prelude - Windows
- 9.0.1 and earlier versions
- Adobe Experience Manager (AEM)
- AEM Cloud Service (CS)
- 6.5.6.0 and earlier versions
- 6.4.8.2 and earlier versions
- 6.3.3.8 and earlier versions
- 6.2 SP1-CFP20 and earlier versions
- AEM Forms add-on
- AEM Forms Service Pack 6 add-on package for AEM 6.5.6.0
- AEM Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2)
- Lightroom Classic - Windows
- 10.0 and earlier versions
- Acrobat DC - Windows & macOS
- 2020.013.20066 and earlier versions
- Acrobat Reader DC - Windows & macOS
- 2020.013.20066 and earlier versions
- Acrobat 2020 - Windows & macOS
- 2020.001.30010 and earlier versions
- Acrobat Reader 2020 - Windows & macOS
- 2020.001.30010 and earlier versions
- Acrobat 2017 - Windows & macOS
- 2017.011.30180 and earlier versions
- Acrobat Reader 2017 - Windows & macOS
- 2017.011.30180 and earlier versions
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Sensitive information disclosure
- Cross-site scripting (XSS)
- Arbitrary code execution
Best practice and Recommendations:
The CERT team encourages users to review Adobe security advisory and apply the necessary updates: