Adobe Photoshop 22.x < 22.5.7 / 23.x < 23.3 Multiple Vulnerabilities (macOS APSB22-20)

high Nessus Plugin ID 159665

Synopsis

Adobe Photoshop installed on remote macOS or Mac OS X host is affected by multiple vulnerabilities.

Description

The version of Adobe Photoshop installed on the remote macOS or Mac OS X host is prior to 22.5.7/23.3. It is, therefore, affected by multiple vulnerabilities as referenced in the apsb22-20 advisory.

- Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
Exploitation of this issue requires user interaction in that a victim must open a malicious file.
(CVE-2022-23205)

- Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PCX file. (CVE-2022-24098)

- Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
Exploitation of this issue requires user interaction in that a victim must open a malicious U3D file.
(CVE-2022-24105)

- Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file.
(CVE-2022-28270)

- Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user.
Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.
(CVE-2022-28271)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Adobe Photoshop version 22.5.7/23.3 or later.

See Also

https://cwe.mitre.org/data/definitions/20.html

https://cwe.mitre.org/data/definitions/125.html

https://cwe.mitre.org/data/definitions/416.html

https://cwe.mitre.org/data/definitions/787.html

https://helpx.adobe.com/security/products/photoshop/apsb22-20.html

Plugin Details

Severity: High

ID: 159665

File Name: macos_adobe_photoshop_apsb22-20.nasl

Version: 1.7

Type: local

Agent: macosx

Published: 4/12/2022

Updated: 7/19/2022

Supported Sensors: Nessus Agent

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2022-28279

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:photoshop

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, installed_sw/Adobe Photoshop

Exploit Ease: No known exploits are available

Patch Publication Date: 4/12/2022

Vulnerability Publication Date: 4/12/2022

Reference Information

CVE: CVE-2022-23205, CVE-2022-24098, CVE-2022-24105, CVE-2022-28270, CVE-2022-28271, CVE-2022-28272, CVE-2022-28273, CVE-2022-28274, CVE-2022-28275, CVE-2022-28276, CVE-2022-28277, CVE-2022-28278, CVE-2022-28279

IAVA: 2022-A-0148-S

CWE: 20, 125, 416, 787