Cisco Talos' Vulnerability Discovery & Research team has recently disclosed multiple critical vulnerabilities across various popular software and operating systems, including Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows. These flaws encompass a range of severe issues such as privilege escalation, information disclosure, remote code execution (RCE), use-after-free, out-of-bounds reads, and type confusion.
Specifically, Adobe Photoshop was found vulnerable to privilege escalation via malformed files, while Apple macOS suffered from an information disclosure flaw in CoreWLAN. Foxit Reader presented two serious vulnerabilities: a remote code execution bug in its JavaScript functionality and a use-after-free flaw exploitable via malicious PDF documents. Microsoft Windows drivers (NETIO.sys, Cloud Files Mini Filter Driver, tcpip.sys) were impacted by multiple vulnerabilities including out-of-bounds reads, use-after-free, privilege escalation, information disclosure, type confusion, and denial-of-service.
All disclosed vulnerabilities have been patched by their respective vendors, aligning with Cisco's disclosure policy. Users are strongly advised to update their software immediately. Snort rule sets have also been updated to detect attempts to exploit these vulnerabilities, and further advisories are available on the Talos Intelligence website.
Top comments (0)