Adobe Connect is prone to multiple security vulnerabilities.
Successfully exploiting these issues may allow attackers to bypass security restrictions, gain unauthorized access to the affected application, obtain sensitive information or to execute arbitrary script code in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. Other attacks are also possible.
Information
CVE-2017-11287
CVE-2017-11288
CVE-2017-11289
CVE-2017-11290
Adobe Connect 9.6.1
Adobe Connect 9.5.7
Adobe Connect 9.5.6
Adobe Connect 9.5.3
Adobe Connect 9.5.2
Adobe Connect 9.4.2
Adobe Connect 9.4
Adobe Connect 9.3
Exploit
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
References:
- Adobe Connect Product Page (Adobe)
- Adobe Homepage (Adobe)
- Security updates available for Adobe Connect | APSB17-35 (Adobe)