
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN313
_____________________________________________________________________

DATE                : 09/06/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Adobe Photoshop versions prior to
                                   21.2.9, 22.4.2.

=====================================================================
https://helpx.adobe.com/security/products/photoshop/apsb21-38.html
_____________________________________________________________________

Security updates available for Adobe Photoshop | APSB21-38


Bulletin ID    Date Published      Priority

APSB21-38      June 08, 2021       3


Summary

Adobe has released updates for Photoshop for Windows and macOS. These
updates resolve multiple  critical vulnerabilities.  Successful
exploitation could lead to arbitrary code execution in the context of
the current user.           


Affected Versions

Product    Affected version    Platform

Photoshop 2020   21.2.8 and earlier versions    Windows and macOS

Photoshop 2021   22.4.1 and earlier versions    Windows and macOS


Solution

Adobe categorizes these updates with the following priority ratings and
recommends users update their installation to the newest version via
the Creative Cloud desktop app’s update mechanism.  For more
information, please reference this help page.   

Product     Updated versions    Platform    Priority

Photoshop 2020    21.2.9     Windows and macOS    3

Photoshop 2021    22.4.2     Windows and macOS    3


Note:

For managed environments, IT administrators can use the Admin Console to
deploy Creative Cloud applications to end users. Refer to this help page
for more information.


Note:

CVE-2021-28582 was resolved by Photoshop 2020 version 21.2.8 and
Photoshop 2021 version 22.4.0 as well.


Vulnerability details

Vulnerability Category  Vulnerability Impact   Severity  CVSS base score
	CVSS vector       CVE Number

Heap-based Buffer Overflow   (CWE-122)   Arbitrary code execution
   Critical     7.8     CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  CVE-2021-28624

Buffer Overflow    (CWE-788)   Arbitrary code execution    Critical
8.8   CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H   CVE-2021-28582


Acknowledgments

Adobe would like to thank the following for reporting the
relevant issues and for working with Adobe to help protect our
customers:

    Yongjun Liu of nsfocus security team (liuyongjun) (CVE-2021-28582)
    Tran Van Khang - khangkito (VinCSS) working with Trend Micro Zero
Day Initiative (CVE-2021-28624)


For more information, visit https://helpx.adobe.com/security.html, or
email PSIRT@adobe.com.

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


