***If you are receiving this email, it is because you subscribed to it. If you have not subscribed and want to unsubscribe, click here. Please do not mark as spam instead. We've had some problems lately with email blacklisting. We'd appreciate if you unsubscribe if you don't want mailings from us.***

Welcome to my December 2024 Patch Monday newsletter! It's our last Patch Monday newsletter for the year!

The biggest vendor this month was Adobe. They released updates for 17 products since last month. The good news is that they didn't have any zero-days to report. As a matter of fact, of the vendors we cover there are no zero-days in the past month to talk about.

Apple released updates to various flavors of macOS as well as watchOS, iPadOS, iOS and visionOS. Mozilla had a fairly busy 30 days with a couple of updates on various dates for Firefox, Firefox for iOS and Firefox ESR. Chrome had 3 version updates covering a total of only 12 vulnerabilities. Zoom didn't release any security updates in the past 30 days. So, it was a fairly slow month and end of the year.

This month's newsletter sponsor, LOGbinder, has just released a new version of Supercharger for Windows Event Collection. I'm mentioning it here because many of you are users and have been asking when the .net 8 update will be released. You can download the latest update here or if you have an existing support contract and don't want to fill out the form then just email sales@logbinder.com.

Be sure to browse the chart below and happy patching!

Follow randyfsmith on X

Subscribe to Randy Franklin Smith on Facebook

So, without further ado, here’s the chart of non-Microsoft 3rd party patches that affect Windows platforms in the past month.

Patch data provided by:

Identifier

Vendor/
Product

Affected Versions

Date Released
by Vendor

Vulnerability Info

Vender Severity / Our Recommedation

Multiple CVE's

Adobe Experience Manager

AEM Cloud Service
6.5.21 and earlier

12/10/2024

Arbitrary Code Execution,
Security Feature Bypass

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Acrobat and Reader

Reader DC/DC Continuous 24.005.20307 and earlier

Classic 2024
24.001.30213 and earlier (Windows)
24.001.30193 and earlier (MacOS)

Classic/Reader 2020

20.005.30730 and earlier (Windows)
20.005.30710 and earlier (MacOS)

12/10/2024

Arbitrary Code Execution,
Application DoS,
Memory Leak

Critical Priority 3: Update at admin's discretion

Multiple CVE's

Adobe Media Encoder

24.6.3 and earlier
25.0 and earlier

12/10/2024

Arbitrary Code Execution,
Application DoS

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Illustrator

2025 29.0.0 and earlier
2024 28.7.2 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

CVE-2024-49537

Adobe After Effects

24.6.2 and earlier
25.0.1 and earlier

12/10/2024

Memory Leak

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Animate

2023 23.0.8 earlier
2024 24.0.5 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe InDesign

ID19.5 and earlier
ID18.5.4 and earlier

12/10/2024

Application DoS,
Arbitrary Code Execution,
Memory Leak

Critical Priority 3: Update at admins discretion

CVE-2024-49513

Adobe PDFL SDK

21.0.0.5 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Connect

12.6 and earlier
11.4.7 and earlier

12/10/2024

Arbitrary Code Execution,
Privilege Escalation,
Security Feature Bypass

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Substance 3D Sampler

4.5.1 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

CVE-2024-52997

Adobe Photoshop

2025 26.0 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Substance 3D Modeler

1.14.1 and earlier

12/10/2024

Arbitrary Code Execution,
Application DoS

Critical Priority 3: Update at admins discretion

CVE-2024-53955

Adobe Bridge

14.1.3 and earlier
15.0 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

CVE-2024-53956

Adobe Premiere Pro

25.0 and earlier
24.6.3 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Substance 3D Painter

10.1.1 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

CVE-2024-53959

Adobe Framemaker

2020 Update 7 and earlier
2022 Update 5 and earlier

12/10/2024

Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

Multiple CVE's

Apple macOS Sequoia

Before 15.2

12/11/2024

Arbitrary Code Execution,
Data Leak,
Data Manipulation,
DoS,
Memory Leak,
Privilege Escalation,
Race Condition,
Security Feature Bypass,
Unauthorized Access,
Unexpected System Termination
Update after testing

Multiple CVE's

Apple macOS Ventura

Before 13.7.2

12/11/2024

Arbitrary Code Execution,
Data Leak,
DoS,
Memory Leak,
Privilege Escalation,
Race Condition,
Security Feature Bypass,
Unauthorized Access
Update after testing

Multiple CVE's

Apple macOS Sonoma

Before 14.7.2

12/11/2024

Arbitrary Code Execution,
Data Leak,
DoS,
Memory Leak,
Privilege Escalation,
Race Condition,
Security Feature Bypass,
Unauthorized Access,
Unexpected System Termination
Update after testing

Multiple CVE's

Apple iOS

iOS/iPadOS before 18.2

12/11/2024

Arbitrary Code Execution,
Data Manipulation,
DoS,
Memory Leak,
Privilege Escalation,
Race Condition,
Security Feature Bypass,
Type Confusion
Update after testing

Multiple CVE's

Apple Safari

Before 18.2

12/11/2024

Information Leak,
Type Confusion,
Unexpected Process Crash
Update after testing

Multiple CVE's

Apple watchOS

Before 11.2

12/11/2024

Arbitrary Code Execution,
Data Leak,
DoS,
Memory Leak,
Privilege Escalation,
Race Condition,
Security Feature Bypass,
Type Confusion,
Unexpected Process Crash
Update after testing

Multiple CVE's

Apple visionOS

Before 2.2

12/11/2024

Arbitrary Code Execution,
Data Leak,
Data Manipulation,
DoS,
Memory Leak,
Race Condition,
Type Confusion,
Unexpected Process Crash
Unexpected System Termination
Update after testing

Multiple CVE's

Google
Chrome

Before 131.0.6778.204 (Linux)

Before 131.0.6778.204/.205 (Windows/Mac)

12/18/2024

Out of Bounds,
Type Confusion,
Use After Free
Update after testing

Multiple CVE's

Mozilla Thunderbird

Before 133

12/11/2024

Arbitrary Code Execution,
Out of Bounds Write,
Spoofing,
Security Feature Bypass,
User Confusion

Update after testing

Multiple CVE's

Mozilla Firefox for iOS

Before 133

11/26/2024

Spoofing,
User Confusion

Update after testing

Multiple CVE's

Mozilla Firefox

Before 133

11/26/2024

Arbitrary Code Execution,
Out of Bounds Write,
Data Leak,
Spoofing,
Security Feature Bypass,
Tapjacking,
Race Condition,
User Confusion

Update after testing

Multiple CVE's

Mozilla Firefox ESR

Before 128.5

11/26/2024

Arbitrary Code Execution,
Out of Bounds Write,
Spoofing,
Security Feature Bypass,
User Confusion

Update after testing

Thanks as always for reading and best wishes on security,

Randy Franklin Smith

Follow randyfsmith on Twitter Subscribe to Randy Franklin Smith on Facebook

Click here to unsubscribe

Ultimate Windows Security is a division of Monterey Technology Group, Inc. ©2006-2024 Monterey Technology Group, All rights reserved. You may forward this email in its entirety but all other rights reserved.

9450 SW Gemini Drive #53822, Beaverton, OR 97008

Note: We do our best to provide quality information and expert commentary but use all information at your own risk.