Copy link to clipboard
Copied
Defender detects vulnerabilities in Artifex Gpl Ghostscript the evidence shows that this has to do with C:\Program Files\Adobe\Adobe Photoshop 2024\convert.exe, this is within photoshop. Anyone else having this or is there any update how we can resolve this vulnerability ?
Thanks
Copy link to clipboard
Copied
I have reported these vulnerabilities to the CERT Vulnerability Disclosure system (sponsored by CISA for industry coordination). They have opened a case based on my report. I'm hoping we will see movement through their work.
Copy link to clipboard
Copied
Thanks for this info, I have filed a report here too. Lets see where that leads.
Copy link to clipboard
Copied
Out of frustration I tried just removing the convert.exe as it's not something actively used, but low and behold the super efficient Adobe automatic update process just replaces it after a couple of days. Not bad for a component that Adobe denies any knowledge of and refuses to accept any responsibility for.
Copy link to clipboard
Copied
Per the ImageMagick git
We don't bundle the Ghostscript library with our project. That library requires a paid license for commercial use so we cannot bundle it. We only search the registry to find the location where it is installed. This look like a bug / false positive in the tool that you are using.
Security vulnerability by ghostscript · ImageMagick/ImageMagick · Discussion #7411 · GitHub
Copy link to clipboard
Copied
Looks like Microsoft have walked away with their tail between their legs 😉
Microsoft Defender for Endpoint is no longer reporting this vulnerability.
So looks like one of our reports / messages got through
Finally !
Copy link to clipboard
Copied
So after all that, there was no vulnerability.
This thread is basically a few people calling the police because there is a prowler outside their home. The police come, no prowler, but those people are still convinced there is one. :sigh:
Copy link to clipboard
Copied
Trouble is even though you know there isn't a prowler, the alarm was still going off until MS acknowledged it and turned it off lol
Copy link to clipboard
Copied
You've got to know when to hold 'em
Know when to fold 'em
Know when to walk away
And know when to run
Find more inspiration, events, and resources on the new Adobe Community
Explore Now