Adobe Photoshop CC Remote Code Execution Vulnerability [CVE-2019-7989]

CVE number – CVE-2019-7989

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of the Folder.rename method when processing JSX files. When opening a JSX file, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to execute code in the context of the current process.

Adobe has issued an update to correct this vulnerability. More details can be found at:
https://helpx.adobe.com/security/products/photoshop/apsb19-44.html

Jason Davies

UK based technology professional, with an interest in computer security and telecoms.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: