Full Report
Adobe security advisory (AV26-776)
Analysis Summary
# Vulnerability: Critical Flaws in Adobe Campaign Classic and Premiere Pro
## CVE Details
*Note: Specific CVE IDs were not detailed in the summary advisory AV26-776; however, based on the linked APSB bulletins (APSB26-120 and APSB26-76), these typically include:*
- **CVE ID:** Multiple (See vendor bulletins)
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** Commonly includes CWE-78 (OS Command Injection), CWE-79 (XSS), and CWE-119 (Memory Corruption).
## Affected Systems
- **Products:**
- Adobe Campaign Classic (ACC)
- Adobe Premiere Pro
- **Versions:**
- ACC v7: 7.4.3 build 9398 and earlier
- Adobe Premiere: 26.2.2 and earlier
- Adobe Premiere Pro: 25.6.5 and earlier
- **Configurations:** Standard installations on Windows and macOS.
## Vulnerability Description
The vulnerabilities range from critical memory corruption issues in Premiere Pro—often triggered by processing maliciously crafted media files—to server-side vulnerabilities in Adobe Campaign Classic. In ACC, these flaws typically involve improper validation of user input, potentially leading to arbitrary code execution or unauthorized data access within the campaign management environment.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (as of the advisory date).
- **Complexity:** Low to Medium.
- **Attack Vector:** Network / Local (via file opening).
## Impact
- **Confidentiality:** High (Potential for data exfiltration).
- **Integrity:** High (Potential for unauthorized modification of data).
- **Availability:** High (Potential for application crashes or system takeover).
## Remediation
### Patches
Adobe recommends updating to the following versions or newer:
- **Adobe Campaign Classic:** Update to version 7.4.4 build 9399 or higher.
- **Adobe Premiere Pro:** Update to the latest versions via the Creative Cloud Desktop application.
### Workarounds
- **Strict File Handling:** Avoid opening project files or media from untrusted or unknown sources.
- **Principle of Least Privilege:** Run applications with the minimum necessary user permissions to limit the impact of a successful exploit.
## Detection
- **Indicators of Compromise:** Unusual outbound network traffic from Adobe Campaign servers; unexpected application crashes when opening specific `.prproj` files.
- **Detection methods and tools:** Use Endpoint Detection and Response (EDR) tools to monitor for suspicious child processes spawned by `Adobe Premiere Pro.exe` or ACC server components.
## References
- Adobe Security Bulletin (Campaign): [https]://helpx.adobe.com/security/products/campaign/apsb26-120.html
- Adobe Security Bulletin (Premiere Pro): [https]://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html
- Adobe PSIRT: [https]://helpx.adobe.com/security/Home.html