Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
13

Vulnerability within photoshop

Community Beginner ,
Jun 14, 2024 Jun 14, 2024

Defender detects vulnerabilities in Artifex Gpl Ghostscript  the evidence shows that this has to do with C:\Program Files\Adobe\Adobe Photoshop 2024\convert.exe, this is within photoshop. Anyone else having this or is there any update how we can resolve this vulnerability ?

 

Thanks 

TOPICS
Windows
14.5K
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe
New Here ,
Jul 25, 2024 Jul 25, 2024

I have reported these vulnerabilities to the CERT Vulnerability Disclosure system (sponsored by CISA for industry coordination). They have opened a case based on my report. I'm hoping we will see movement through their work.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Jul 26, 2024 Jul 26, 2024

Thanks for this info, I have filed a report here too. Lets see where that leads.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Jul 26, 2024 Jul 26, 2024

Out of frustration I tried just removing the convert.exe as it's not something actively used, but low and behold the super efficient Adobe automatic update process just replaces it after a couple of days. Not bad for a component that Adobe denies any knowledge of and refuses to accept any responsibility for.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Jul 29, 2024 Jul 29, 2024

Per the ImageMagick git

We don't bundle the Ghostscript library with our project. That library requires a paid license for commercial use so we cannot bundle it. We only search the registry to find the location where it is installed. This look like a bug / false positive in the tool that you are using.

Security vulnerability by ghostscript · ImageMagick/ImageMagick · Discussion #7411 · GitHub

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Aug 21, 2024 Aug 21, 2024

Looks like Microsoft have walked away with their tail between their legs 😉
Microsoft Defender for Endpoint is no longer reporting this vulnerability.
So looks like one of our reports / messages got through
Finally !

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
LEGEND ,
Aug 21, 2024 Aug 21, 2024

So after all that, there was no vulnerability.

This thread is basically a few people calling the police because there is a prowler outside their home. The police come, no prowler, but those people are still convinced there is one. :sigh:

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Aug 21, 2024 Aug 21, 2024

Trouble is even though you know there isn't a prowler, the alarm was still going off until MS acknowledged it and turned it off lol

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
LEGEND ,
Aug 21, 2024 Aug 21, 2024
LATEST

You've got to know when to hold 'em
Know when to fold 'em
Know when to walk away
And know when to run

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines