Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Multiple Critical Vulnerabilities in Adobe Products-Aug 2022

Issued: 
Wednesday, 24 August, 2022
Last Revision: 
Wednesday, 24 August, 2022
Vendor: 
Severity Level: 
Summary: 

Adobe has issued security update for August 2022, which address multiple critical and important vulnerabilities in its products.  It appears that none of Adobe's bugs fixed in this month are publicly known or under active attack. 

 

Adobe products that are patched in this month security update includes- Adobe Commerce, Adobe Acrobat and Reader, Adobe Illustrator, Adobe Frame maker, and Adobe Premiere Elements. 

 

Adobe has fixed problem of - arbitrary code execution, privilege escalation, security feature bypass, and memory leak.

 

CVE/Vulnerability

Description 

Severity

CVE-2022-34253

Arbitrary code execution

9.1

CVE-2022-34254

Arbitrary code execution

8.5

CVE-2022-34255

Privilege escalation

8.3

CVE-2022-34256

Privilege escalation

8.2

CVE-2022-35665

Arbitrary code execution

7.8

CVE-2022-35666

Arbitrary code execution

7.8

CVE-2022-35667

Arbitrary code execution

7.8

CVE-2022-34260

Arbitrary code execution

7.8

CVE-2022-34263

Arbitrary code execution

7.8

CVE-2022-35673- CVE-2022-35677

Arbitrary code execution

7.8

CVE-2022-34235

Privilege escalation

8.8

 

 

Table 1: Vulnerability details 

 

 

Affected Product(s)

Version

Platform

Adobe Commerce

2.4.3-p2 and earlier Versions

2.3.7-p3 and earlier Versions

2.4.4 and earlier versions 

All

Magento Open Source

2.4.3-p2 and earlier versions

2.3.7-p3 and earlier versions

2.4.4 and earlier versions 

All

Acrobat DC

22.001.20169 and earlier Versions

 

Windows &  macOS

Acrobat Reader DC

22.001.20169 and earlier Versions

Windows &  macOS

Acrobat 2020

20.005.30362 and earlier Versions

Windows &  macOS

Acrobat Reader 2020

20.005.30362 and earlier Versions

Windows &  macOS

Acrobat 2017

17.012.30249 and earlier  Versions

 

Windows &  macOS

 

Acrobat Reader 2017

17.012.30249 and earlier Versions

 

Windows &  macOS

 

Illustrator 2022

26.3.1 and earlier versions 

25.4.6 and earlier versions 

 

Windows &  macOS

Adobe FrameMaker

2019 Release Update 8 a

 

Windows

2020 Release Update 4 and earlier versions

Adobe

Premiere Elements

2022 (Version 20.0)

 

 

Windows &  macOS

 

 

                                                                                       Table 2: Vulnerable versions 

 

Recommendation: 

 

Organizations are strongly encouraged to review and apply appropriate update using the vendor provided instruction in the “Solution” section of Adobe security bulletin, particularly patches for critical vulnerabilities.