CVE-2016-0952
published 2016-02-10CVE-2016-0952: Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of…
PriorityP263critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
20.55%
97.2th percentile
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | bridge_cc | <= 6.1 | — |
| adobe | photoshop_cc | <= 16.1.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition is a malformed PNG file with an invalid uint32 CRC checksum, causing heap memory corruption — inspect PNG files for invalid CRC values in chunks before opening in Photoshop CC or Bridge CC. ↗
- →Exploitation requires user interaction (opening a malicious file); monitor for suspicious .png file opens in Adobe Photoshop CC (≤16.1.1) and Bridge CC (≤6.1.1) processes. ↗
- →Both PoC PNG files must be present in the same folder to trigger the vulnerability in Bridge CC — alert on co-located suspicious PNG pairs dropped to the same directory. ↗
- ·Affected versions are Photoshop CC 16.1.1 (2015.1.1) and earlier, and Bridge CC 6.1.1 and earlier (Windows platform); patched by Adobe in APSB16-03 released 2016-02-09. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m85w-w4cf-h327: Adobe Photoshop CC 2014 before 15
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-0952 [CRITICAL] CWE-119 GHSA-m85w-w4cf-h327: Adobe Photoshop CC 2014 before 15
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.
GHSA
GHSA-xpjm-p24r-pm4q: Adobe Photoshop CC 2014 before 15
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-0953 [CRITICAL] CWE-119 GHSA-xpjm-p24r-pm4q: Adobe Photoshop CC 2014 before 15
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.
GHSA
GHSA-3j54-7r73-qgxr: Adobe Photoshop CC 2014 before 15
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-0951 [CRITICAL] CWE-119 GHSA-3j54-7r73-qgxr: Adobe Photoshop CC 2014 before 15
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.
No detection rules found.
Exploit-DB
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
exploitdb·2018-08-22
CVE-2018-0952 Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
---
SystemCollector
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
Affected Products
Windows 10
Windows Server
Windows Server 2016
Visual Studio 2015 Update 3
Visual Studio 2017
Summary
The Diagnostics Hub Packaging library, used by Windows Standard Collector Service, can be forced to copy an arbitrary file to an arbitrary location due to lack of client impersonation in DiagnosticsHub.StandardCollector.Runtime.dll.
Here is a detailed write-up on how this vulnerability was found and exploited: Privilege Escalation Vulnerability in Windows Standard Collector Service.
Technical Details
The Standard Collector Service allows for a several values to be defined when c
Exploit-DB
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
exploitdb·2016-02-09
CVE-2016-0952 Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
---
#####################################################################################
Application: Adobe Photoshop CC & Bridge CC PNG file parsing memory corruption
Platforms: Windows
Versions: Bridge CC 6.1.1 and earlier versions
Version: Photoshop CC 16.1.1 (2015.1.1) and earlier versions
CVE; 2016-0952
Author: Francis Provencher of COSIG
Twitter: @COSIG_
#####################################################################################
1) Introduction
2) Report Timeline
3) Technical details
4) POC
#####################################################################################
1) Introduction
Adobe Photoshop is a raster graphics editor developed and published by Adobe Systems for Windows and
No writeups or analysis indexed.
2016-02-10
Published