Rewterz
Lazarus aka Hidden Cobra APT Group – Active IOCs
October 9, 2024
Rewterz
Multiple D-Link DIR-605L Vulnerabilities
October 10, 2024

Multiple Adobe Products Zero-Day Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-45146 CVSS:7.8

Adobe Dimension could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. By persuading a victim to open a specially crafted SKP file, a remote attacker could exploit this vulnerability to execute code on the system with the privileges of the victim or cause the application to crash.

CVE-2024-45138 CVSS:7.8

Adobe Substance 3D Stager could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. By persuading a victim to open a specially crafted SKP file, a remote attacker could exploit this vulnerability to execute code on the system with the privileges of the victim or cause the application to crash.

Impact

  • Code Execution

Indicators of Compromise

CVE

  • CVE-2024-45146
  • CVE-2024-45138

Affected Vendors

Adobe

Affected Products

  • Adobe Dimension - 4.0.3
  • Adobe Substance3D - Stager - 3.0.3

Remediation

Refer to Adobe Security Advisory for patch, upgrade or suggested workaround information.

CVE-2024-45146

CVE-2024-45138