===================================================================== CERT-Renater Note d'Information No. 2021/VULN395 _____________________________________________________________________ DATE : 18/08/2021 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Windows, macOS running Adobe Photoshop versions prior to 21.2.11, 22.5. ===================================================================== https://helpx.adobe.com/security/products/photoshop/apsb21-68.html _____________________________________________________________________ Security updates available for Adobe Photoshop | APSB21-68 Bulletin ID Date Published Priority APSB21-68 August 17, 2021   3 Summary Adobe has released updates for Photoshop for Windows and macOS. These updates resolve multiple critical vulnerabilities.  Successful exploitation could lead to arbitrary code execution in the context of the current user.                     Affected Versions Product Affected version Platform Photoshop 2020 21.2.10 and earlier versions Windows and macOS Photoshop 2021 22.4.3  and earlier versions  Windows and macOS Solution Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app’s update mechanism.  For more information, please reference this help page.    Product Updated versions Platform Priority Photoshop 2020 21.2.11 Windows and macOS 3 Photoshop 2021 22.5 Windows and macOS 3 Note: For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information. Vulnerability details Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number Heap-based Buffer Overflow (CWE-122) Arbitrary code execution Critical 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-36065 Out-of-bounds Write (CWE-787)  Arbitrary code execution  Critical  7.8  CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-36066 Acknowledgments Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers: Yongjun Liu of nsfocus security team (liuyongjun) (CVE-2021-36065) Francis Provencher {PRL} working with Trend Micro Zero Day Initiative ( CVE-2021-36066) For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================