Security Patch Watch: Adobe, Macromedia, Symantec

執筆者
Ryan Naraine
Ryan Naraine
Published: Jun 13, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A security flaw in the installation of Adobes License Management Service has put customers at risk of privilege escalation attacks, according to a warning from the software maker.

An advisory from Adobe Systems Inc. said the vulnerability affects multiple products, including the widely used Adobe Photoshop CS, Adobe Creative Suite 1.0 and Adobe Premiere Pro 1.x.

Security alerts aggregator Secunia rates the flaw as “moderately critical” and warned that a successful attack could give a malicious hacker access to a vulnerable system.

According to Adobe, the vulnerability exists due to a flaw in the installation of the License Management Service, which ships with various Adobe products that require product activation.

“If exploited, an unauthorized person can exploit this to run a program with administrator privileges,” the company added.

“Adobe is not aware of any report of malicious code that exploits this vulnerability. Adobe wants to be proactive by providing the users a simple mechanism to protect their systems,” the company said.

Customers using the latest version of Photoshop (version CS2) or Adobe Creative Suite (version CS2) are not exposed to the vulnerability, which affects products running on the Windows OS platform only.

The company has provided updates with instructions on its Web site.

Multiple Macromedia Product Patches

Software developer Macromedia Inc. has released patches rated “important” for a privilege escalation vulnerability in multiple products in the Macromedia MX 2004 suite.

The bug is similar to the license management flaw patched by Adobe and affects a range of Macromedia applications, including Studio, Studio with Flash Professional, Flash Professional, Flash, FreeHand, Dreamweaver, Fireworks, and Director, Captivate and Contribute 2.x.

According to a Macromedia alert, Windows versions of the Macromedia installers and eLicensing client install a service with permissions that allow any member of the “Users” group to modify the service settings. This may allow local users to obtain the permissions of the “Local System” account.

“This potential vulnerability does not affect products installed on machines with a single user, and it cannot be exploited remotely,” the company said.

Advertisement

Hotfixes and updating instructions are available for download here.

Symantec Corrects pcAnywhere Flaw

Internet security specialist Symantec Corp. has rolled out new versions of its pcAnywhere remote control tool to fix a potentially serious security hole.

In an online advisory, Symantec warned that the flaw could be exploited by malicious, local users to gain escalated privileges.

Affected products include pcAnywhere 9.x, 10.x and 11.x.

/zimages/4/28571.gifRead the full story on Publish.com: Security Patch Watch: Adobe, Macromedia, Symantec

/zimages/4/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。