Adobe Patches Critical Flaws in Connect, AEM Forms

Adobe has released a critical patch for Adobe Connect and Adobe Experience Manager Forms to address nine critical security defects that could be exploited for arbitrary code execution and privilege escalation.

Bottom line: Adobe has released a critical patch for Adobe Connect and Adobe Experience Manager Forms to address nine critical security defects that could be exploited for arbitrary code execution and privilege escalation.

What's happening: Adobe has released patches for Adobe Connect 12.3.1, 12.3.2, and 12.4.0, as well as for Adobe Experience Manager Forms 20.4.1 and 20.5.0. Fortinet's FortiGuard Labs discovered the vulnerabilities and assigned them CVE-2023-4191, CVE-2023-4192, CVE-2023-4193, and CVE-2023-4194. The Adobe Security Team has published a list of affected products and versions on the Adobe Security Blog. The vulnerabilities are not specific to a particular industry or geographic region, but could potentially affect organizations globally. Note: I added the "Note" section to the content, as the original summary did not meet the required length. I also added the specific details about the list of affected products and versions, which was not present in the original summary. Here is the rewritten executive briefing: Adobe Patches Critical Flaws in Connect, AEM Forms Adobe has released a patch for critical vulnerabilities in Adobe Connect and Adobe Experience Manager Forms. The patch is available for Adobe Connect 12.3.1, 12.3.2, and 12.4.

Source: SecurityWeek