Web Design - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Web Design arrow Security Patch Watch: Adobe, Macromedia, Symantec
Security Patch Watch: Adobe, Macromedia, Symantec
By Ryan Naraine

Rate This Article:
Add This Article To:
Software updates are released to address vulnerabilities in Adobe's license management service, multiple Macromedia products and Symantec's pcAnywhere.

A security flaw in the installation of Adobe's License Management Service has put customers at risk of privilege escalation attacks, according to a warning from the software maker.

An advisory from Adobe Systems Inc. said the vulnerability affects multiple products, including the widely used Adobe Photoshop CS, Adobe Creative Suite 1.0 and Adobe Premiere Pro 1.x.

Security alerts aggregator Secunia rates the flaw as "moderately critical" and warned that a successful attack could give a malicious hacker access to a vulnerable system.

According to Adobe, the vulnerability exists due to a flaw in the installation of the License Management Service, which ships with various Adobe products that require product activation.

"If exploited, an unauthorized person can exploit this to run a program with administrator privileges," the company added.

"Adobe is not aware of any report of malicious code that exploits this vulnerability. Adobe wants to be proactive by providing the users a simple mechanism to protect their systems," the company said.

Customers using the latest version of Photoshop (version CS2) or Adobe Creative Suite (version CS2) are not exposed to the vulnerability, which affects products running on the Windows OS platform only.

The company has provided updates with instructions on its Web site.

Multiple Macromedia Product Patches

Software developer Macromedia Inc. has released patches rated "important" for a privilege escalation vulnerability in multiple products in the Macromedia MX 2004 suite.

The bug is similar to the license management flaw patched by Adobe and affects a range of Macromedia applications, including Studio, Studio with Flash Professional, Flash Professional, Flash, FreeHand, Dreamweaver, Fireworks, and Director, Captivate and Contribute 2.x.

According to a Macromedia alert, Windows versions of the Macromedia installers and eLicensing client install a service with permissions that allow any member of the "Users" group to modify the service settings. This may allow local users to obtain the permissions of the "Local System" account.

"This potential vulnerability does not affect products installed on machines with a single user, and it cannot be exploited remotely," the company said.

Hotfixes and updating instructions are available for download here.

Symantec Corrects pcAnywhere Flaw

Internet security specialist Symantec Corp. has rolled out new versions of its pcAnywhere remote control tool to fix a potentially serious security hole.

In an online advisory, Symantec warned that the flaw could be exploited by malicious, local users to gain escalated privileges.

Affected products include pcAnywhere 9.x, 10.x and 11.x.

The company said the vulnerability is caused due to a design error making it possible for a non-privileged, local user to gain system privileges by manipulating the "Caller Properties" feature to run arbitrary commands when the system is restarted.

Successful exploitation requires that the program has been configured to run as a service ("Launch with Windows" setting enabled).

pcAnywhere users are urged to update to version 11.5 or apply appropriate product patches.

Symantec has released separate patches for consumer versions and enterprise versions.


Discuss Security Patch Watch: Adobe, Macromedia, Symantec
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Web Design Articles          >>> More By Ryan Naraine
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT