Full Report
Adobe security advisory (AV26-760)
Analysis Summary
# Vulnerability: Critical and Important Vulnerabilities in Adobe Campaign Classic
## CVE Details
*Note: Specific CVE IDs were not listed in the summary advisory. Based on the advisory ID APSB26-114, multiple CVEs are typically addressed in such bundles.*
- **CVE ID:** CVE-YYYY-XXXXX (Multiple)
- **CVSS Score:** Up to 9.8 (Critical) - *Estimated based on standard Adobe Critical rankings for this product type.*
- **CWE:** Typically includes CWE-79 (XSS), CWE-22 (Path Traversal), or CWE-502 (Deserialization).
## Affected Systems
- **Products:** Adobe Campaign Classic (ACC)
- **Versions:**
- All versions prior to or equal to **7.4.3 build 9397**
- This affects both Windows and Linux deployments.
- **Configurations:** All standard installations of Adobe Campaign Classic.
## Vulnerability Description
While the specific technical breakdown is detailed in the full APSB26-114 bulletin, these updates for Adobe Campaign Classic typically address flaws involving:
1. **Improper Input Validation:** Which could lead to arbitrary code execution.
2. **Security Feature Bypass:** Allowing unauthorized access to sensitive data or administrative functions.
3. **Cross-Site Scripting (XSS):** Potentially allowing attackers to inject malicious scripts into the victim's browser session.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation in the wild as of the advisory date).
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential unauthorized access to marketing databases and customer PII).
- **Integrity:** High (Potential for unauthorized modification of campaigns and system files).
- **Availability:** High (Potential for service disruption).
## Remediation
### Patches
Adobe recommends that users update their installations to the following version:
- **Adobe Campaign Classic 7.4.3 build 9398** or later.
### Workarounds
- There are no officially supported workarounds. Immediate patching is the recommended course of action.
- Ensure the principle of least privilege is applied to service accounts running Adobe Campaign.
## Detection
- **Indicators of Compromise:** Monitor for unusual administrative login attempts or unexpected outbound traffic from the Campaign Classic application server.
- **Detection methods:** Utilize Vulnerability Scanners (such as Nessus or Qualys) to identify outdated build numbers (v7.4.3 Build 9397 and below).
## References
- Adobe Security Bulletin APSB26-114: hxxps[://]helpx[.]adobe[.]com/security/products/campaign/apsb26-114[.]html
- Adobe PSIRT: hxxps[://]helpx[.]adobe[.]com/security/Home[.]html
- Canadian Centre for Cyber Security Advisory (AV26-760): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/adobe-security-advisory-av26-760