Adobe Patches Code Execution Flaws in Connect, Creative Cloud, Framemaker

Source
Advertisement


In the Creative Cloud desktop application, Adobe fixed three flaws rated critical, including arbitrary file overwrite and OS command injection issues that can lead to code execution, and an improper input validation issue that can be exploited for privilege escalation.

In its Connect product, the company addressed one critical input validation issue that can result in arbitrary code execution and three important-severity reflected cross-site scripting (XSS) flaws that can allow an attacker to execute arbitrary JavaScript code in the targeted user’s browser. XSS attacks typically require the victim to click on a specially crafted link.

Advertisement