SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Adobe Security Updates December 2019

Adobe Security Updates December 2019

Dec 12, 2019By Vidita V Koushik2 min read

Adobe released its December 2019 Security Updates addressing 25 vulnerabilities in Adobe Acrobat and Reader, Photoshop CC, Brackets and ColdFusion. Seventeen of these vulnerabilities are rated Critical vulnerabilities and a majority of the them are in Adobe Acrobat and Reader. As is the case with most critical vulnerabilities, these allow an attacker to execute arbitrary code in the context of the current user.

Adobe Acrobat and Reader

The update for Adobe Acrobat and Reader comprises of fixes for 14 critical and 7 important vulnerabilities. These flaws exist due to out-of-bounds write, use after free, heap overflow, untrusted pointer dereference, security bypass and buffer errors in the software. However, all the critical vulnerabilities lead to Arbitrary Code Execution and the others could result in information disclosure or privilege escalation. Also, a patch management solution can apply patches to these vulnerabilities.

Adobe Photoshop CC

Two critical memory corruption bugs were addressed in Adobe Photoshop CC. Moreover, successful exploitation of these bugs could lead to Arbitrary Code Execution in the context of the current user.

Adobe Brackets

A critical command injection vulnerability was resolved in Adobe Brackets, which could lead to Arbitrary Code Execution in the context of the current user.

Adobe ColdFusion

An important privilege escalation vulnerability fixed in Adobe ColdFusion. Also, the flaw is due to the presence of insecure inherited permissions of default installation directory in the software.

Adobe Security Bulletin summary for November 2019:

  1. Product : Adobe Acrobat and ReaderCVE’s/Advisory : APSB19-55, CVE-2019-16444, CVE-2019-16445, CVE-2019-16446, CVE-2019-16448, CVE-2019-16449, CVE-2019-16450, CVE-2019-16451, CVE-2019-16452, CVE-2019-16453, CVE-2019-16454, CVE-2019-16455, CVE-2019-16456, CVE-2019-16457, CVE-2019-16458, CVE-2019-16459, CVE-2019-16460, CVE-2019-16461, CVE-2019-16462, CVE-2019-16463, CVE-2019-16464 and then CVE-2019-16465Severity : CriticalImpact : Arbitrary Code Execution?, Information Disclosure, Privilege Escalation

2. Product : Adobe Photoshop CCCVE’s/Advisory : APSB19-56, CVE-2019-8253 and then CVE-2019-8254

Severity : CriticalImpact : Arbitrary code execution

3. Product : Adobe BracketsCVE’s/Advisory : APSB19-57 and then CVE-2019-8255Severity : CriticalImpact : Arbitrary code execution

4. Product : Adobe ColdFusionCVE’s/Advisory : APSB19-58 and then  CVE-2019-8256Severity : ImportantImpact : Privilege Escalation

SecPod Saner detects these vulnerabilities and automatically fixes it by applying security updates. Download Saner now and keep your systems updated and secure.

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026