Rewterz Threat Advisory – Google Chrome Multiple Vulnerabilities
April 29, 2020Rewterz Threat Alert – Phishing Campaign Delivering Agent Tesla Malware
April 29, 2020Rewterz Threat Advisory – Google Chrome Multiple Vulnerabilities
April 29, 2020Rewterz Threat Alert – Phishing Campaign Delivering Agent Tesla Malware
April 29, 2020Severity
High
Analysis Summary
CVE-2020-9558
Adobe Bridge could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2020-9557
Adobe Bridge could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2020-9568
Adobe Bridge could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2020-9563
Adobe Bridge is vulnerable to a heap-based buffer overflow. By persuading a victim to open a specially-crafted document, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2020-9562
Adobe Bridge is vulnerable to a heap-based buffer overflow. By persuading a victim to open a specially-crafted document, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2020-9555
Adobe Bridge is vulnerable to a stack-based buffer overflow. By persuading a victim to open a specially-crafted document, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
Impact
- Exposure of sensitive data
- Arbitrary code execution
Affected Vendors
Adobe
Affected Products
Adobe Bridge 10.0.4 |
Remediation
Refer to Adobe Security Bulletin APSB20-19 for upgraded patch.https://helpx.adobe.com/security/products/bridge/apsb20-19.html |