SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Adobe Security Updates December 2019

Adobe Security Updates December 2019

Dec 12, 2019By Vidita V Koushik2 min read

Adobe released its December 2019 Security Updates addressing 25 vulnerabilities in Adobe Acrobat and Reader, Photoshop CC, Brackets and ColdFusion. Seventeen of these vulnerabilities are rated Critical vulnerabilities and a majority of the them are in Adobe Acrobat and Reader. As is the case with most critical vulnerabilities, these allow an attacker to execute arbitrary code in the context of the current user.

Adobe Acrobat and Reader

The update for Adobe Acrobat and Reader comprises of fixes for 14 critical and 7 important vulnerabilities. These flaws exist due to out-of-bounds write, use after free, heap overflow, untrusted pointer dereference, security bypass and buffer errors in the software. However, all the critical vulnerabilities lead to Arbitrary Code Execution and the others could result in information disclosure or privilege escalation. Also, a patch management solution can apply patches to these vulnerabilities.

Adobe Photoshop CC

Two critical memory corruption bugs were addressed in Adobe Photoshop CC. Moreover, successful exploitation of these bugs could lead to Arbitrary Code Execution in the context of the current user.

Adobe Brackets

A critical command injection vulnerability was resolved in Adobe Brackets, which could lead to Arbitrary Code Execution in the context of the current user.

Adobe ColdFusion

An important privilege escalation vulnerability fixed in Adobe ColdFusion. Also, the flaw is due to the presence of insecure inherited permissions of default installation directory in the software.

Adobe Security Bulletin summary for November 2019:

  1. Product : Adobe Acrobat and ReaderCVE’s/Advisory : APSB19-55, CVE-2019-16444, CVE-2019-16445, CVE-2019-16446, CVE-2019-16448, CVE-2019-16449, CVE-2019-16450, CVE-2019-16451, CVE-2019-16452, CVE-2019-16453, CVE-2019-16454, CVE-2019-16455, CVE-2019-16456, CVE-2019-16457, CVE-2019-16458, CVE-2019-16459, CVE-2019-16460, CVE-2019-16461, CVE-2019-16462, CVE-2019-16463, CVE-2019-16464 and then CVE-2019-16465Severity : CriticalImpact : Arbitrary Code Execution?, Information Disclosure, Privilege Escalation

2. Product : Adobe Photoshop CCCVE’s/Advisory : APSB19-56, CVE-2019-8253 and then CVE-2019-8254

Severity : CriticalImpact : Arbitrary code execution

3. Product : Adobe BracketsCVE’s/Advisory : APSB19-57 and then CVE-2019-8255Severity : CriticalImpact : Arbitrary code execution

4. Product : Adobe ColdFusionCVE’s/Advisory : APSB19-58 and then  CVE-2019-8256Severity : ImportantImpact : Privilege Escalation

SecPod Saner detects these vulnerabilities and automatically fixes it by applying security updates. Download Saner now and keep your systems updated and secure.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Adobe Security Updates December 2019 | SecPod