CVE-2019-7989: Adobe Photoshop JSX File ExtendScript Folder.remove Insufficient UI Warning Denial-of-Service Vulnerability
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the File.read method when processing JSX files. When opening a JSX file, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to disclose information in the context of the current process.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the File.readch method when processing JSX files. When opening a JSX file, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to disclose information in the context of the current process.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the File.readln method when processing JSX files. When opening a JSX file, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to disclose information in the context of the current process.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the app.system method when processing JSX files. When opening a JSX file, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to execute code in the context of the current process.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the File.copy method when processing JSX files. When opening a JSX file, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7989?
CVE-2019-7989 is a vulnerability that allows remote attackers to disclose sensitive information on affected installations of Adobe Photoshop.
How can this vulnerability be exploited?
This vulnerability can be exploited when the target visits a malicious page or opens a malicious file.
Which software versions are affected by CVE-2019-7989?
Adobe Photoshop CC versions 19.1.8 and 20.0 up to 20.0.5 are affected by this vulnerability.
What is the severity of CVE-2019-7989?
CVE-2019-7989 has a severity rating of 8.8, which is considered high.
How do I fix CVE-2019-7989?
To fix CVE-2019-7989, update to the latest version of Adobe Photoshop CC.