QID 730727
Date Published: 2023-02-20
QID 730727: Adobe Connect Security Feature Bypass Vulnerability (APSB23-05)
Adobe Connect is software used to create information and general presentations, online training materials, web conferencing, learning modules and user desktop sharing.
CVE-2021-43014: Adobe Connect is vulnerable to Cross-Site Request Forgery that allows Arbitrary file system write
Affected Versions:
Adobe Connect versions 11.4.5 and earlier versions
Adobe Connect versions 12.1.5 and earlier versions
QID Detection Logic (Unauthenticated):
This QID reads the version text file in an unauthenticated request to see if it is vulnerable.
On Successful exploitation, the attacker would be able to write arbitrary file system on the target.
Solution
Customers are advised to follow the patch procedure provided by Adobe. Furthermore information can be obtained from APSB23-05
Vendor References
CVEs related to QID 730727
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| apsb23-05 |
|