Quote:Adobe’s Patch Tuesday updates for April 2019 address 43 vulnerabilities affecting the company’s Acrobat and Reader, Flash Player, Shockwave Player, Dreamweaver, XD, InDesign, Experience Manager Forms, and Bridge CC products.
In the Windows and macOS versions of Acrobat and Reader software, Adobe fixed 21 security holes, including critical memory corruption bugs that can be exploited for arbitrary code execution.
While threat actors exploiting Reader vulnerabilities in attacks is not unheard of, the priority rating assigned by the company to the latest flaws suggests that it does not expect them to be exploited in the near future.
In Flash Player, Adobe patched a critical code execution flaw and an important information disclosure issue. Flash Player flaws are often exploited in the wild, but the company does not believe these security holes will be exploited any time soon.
A total of seven vulnerabilities have been resolved by the tech giant in Shockwave Player for Windows. These weaknesses, all described as critical memory corruptions that can lead to arbitrary code execution, were reported to Adobe by Honggang Ren of Fortinet's FortiGuard Labs.
SOURCE: https://www.securityweek.com/adobe-patch...t-products