Adobe Security Updates – 13 June 2024

Adobe has released security updates to fix multiple vulnerabilities across several Adobe products.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, escalate privilege, obtain sensitive information, trigger denial of services attacks, or execute arbitrary code and gain access to the affected products.

Sample of the addressed vulnerabilities:

1. Adobe Commerce and Magento Open Source Code Execution Vulnerability (CVE-2024-34102):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. Adobe ColdFusion Information Disclosure Vulnerability (CVE-2024-34112):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

Affected Products:

  • Adobe ColdFusion.
  • Adobe Commerce.
  • Adobe Experience Manager.
  • Adobe Audition.
  • Adobe Media Encoder.
  • Adobe FrameMaker Publishing.
  • Adobe Substance 3D Stager.
  • Adobe Creative Cloud Desktop.
  • Adobe Photoshop.
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Adobe Security Advisory

References