---
title: "Adobe fixes only 25 out of 60 vulnerabilities (Patch!) - Ventas de Seguridad"
description: "The latest news for Latin American integrators, contractors and wholesalers in electronic security."
url: "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html"
date: "2026-07-23T17:18:01+00:00"
language: "en-GB"
---

#  [ Adobe fixes only 25 out of 60 vulnerabilities (Patch!)](https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html "Adobe fixes only 25 out of 60 vulnerabilities (Patch!)")

      Details     19 August 2012           Adobe's security bulletins in August address 26 critical vulnerabilities related to remote code execution. Adobe Systems Incorporated, has released three bulletins this month (APSB12-16/17/18) that fix a total of 26 vulnerabilities labeled as "critical", which can potentially lead to code execution: 20 in the Acrobat family, 5 in Shockwave Player and one in Flash player. Some of these vulnerabilities are already being exploited by...Co... Adobe's security bulletins in August address 26 critical vulnerabilities related to remote code execution.

Adobe Systems Incorporated, has released three bulletins this month (APSB12-16/17/18) that fix a total of 26 vulnerabilities labeled as "critical", which can potentially lead to code execution: 20 in the Acrobat family, 5 in Shockwave Player and one in Flash player.

Some of these vulnerabilities are already being exploited by attackers who embed Flash animations in Word documents.

Google Chrome users will be updated automatically.

- Publicidad -

As a reminder of the announcement made by Adobe in June, from August 15 the versions of Flash Player for Android will no longer be officially downloaded from the Google Play Store, although security updates will continue to be provided until September 13, 2013.

Following the release of Adobe's latest bulletin for Reader and Acrobat (APSB12-16), researchers Mateusz Jurczyk and Gynvael Coldwind of the Google Security Team (and former colleagues at Hispasec) have published their analysis in which they conclude that Adobe, apart from leaving Linux users unprotected (as no fixed version has yet been published) has not resolved all the vulnerabilities reported by themselves.

The group was in charge of the "fuzzing" project of the PDF reader integrated in Google Chrome. They detected more than 50 problems. The most critical ones have already been corrected in the browser reader. Given the "success" of the operation, they decided to perform the same tests against the Adobe reader.

They concluded their tests with 60 failures. 31 problems could be "trivially exploitable" and 9 potentially exploitable. In June, they contacted Adobe's security team, who were very collaborative from the start. But the latest bulletin only corrects about 25 of these flaws in its 12 CVEs.

Thus, the researchers conclude that there are about 16 problems not yet corrected, which could represent perhaps 8 serious vulnerabilities (since 25 problems gave rise to 12 CVEs). Keep in mind that the problems detected by "fuzzing" can originate in the same vulnerability, and be corrected with the same modification of the code.

Adobe says it will fix it in the future. August 27 marks the 60-day limit that the researchers imposed as a condition for giving details, but since Adobe has no intention of publishing an out-of-cycle newsletter, it appears that the deadline will be met without patches. So they have decided, now, to make available to all their discoveries, given the risk that users face.

Source: Hispasec I, II

- Publicidad -

**[See original.](http://feedproxy.google.com/~r/NoticiasSeguridadInformatica/~3/ZgqLRIwMWmI/adobe-corrige-solo-25-de-60.html "Adobe corrige sólo 25 de 60 vulnerabilidades (Parc")**

      ###  No comments

• If you're already registered, please log in first. Your email will not be published.

###  Comments are closed

 The comments for this content are closed.

## Schema

```json
{ "@context": "https://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Inicio", "item": "https://www.ventasdeseguridad.com/en" }, { "@type": "ListItem", "position": 2, "name": "Latest News", "item": "https://www.ventasdeseguridad.com/en/news/latest-news.html" }, { "@type": "ListItem", "position": 3, "name": "Cyber Security", "item": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security.html" }, { "@type": "ListItem", "position": 4, "name": "Adobe fixes only 25 out of 60 vulnerabilities (Patch!)", "item": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html" } ] }
```

```json
{ "@context": "https://schema.org", "@type": "VideoObject", "name": "Adobe fixes only 25 out of 60 vulnerabilities (Patch!)", "description": "Adobe&#039;s security bulletins in August address 26 critical vulnerabilities related to remote code execution. Adobe Systems Incorporated, has released three bulletins this month (APSB12-16/17/18) that fix a total of 26 vulnerabilities labeled as &quot;critical&quot;, which can potentially lead to code execution: 20 in the Acrobat family, 5 in Shockwave Player and one in Flash player. Some of these vulnerabilities are already being exploited by...Co...", "thumbnailUrl": "https://www.ventasdeseguridad.com/", "uploadDate": "2012-08-19T14:34:01-05:00", "contentUrl": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html" }
```

```json
{ "@context": "https://schema.org", "@type": "NewsArticle", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html" }, "headline": "Adobe fixes only 25 out of 60 vulnerabilities (Patch!) - Ventas de Seguridad", "description": "The latest news for Latin American integrators, contractors and wholesalers in electronic security.", "image": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/" }, "publisher": { "@type": "Organization", "name": "Ventas de Seguridad", "logo": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/vds.png" } }, "author": { "@type": "Person", "name": "Max Jaramillo", "url": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html" }, "datePublished": "2012-08-19T14:34:01-05:00", "dateCreated": "2012-08-19T13:31:00-05:00", "dateModified": "2022-04-25T18:22:46-05:00" }
```

```json
{ "@context": "https://schema.org", "@type": "Article", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html" }, "headline": "Latest News", "description": "The latest news for Latin American integrators, contractors and wholesalers in electronic security.", "image": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/vds.png" }, "publisher": { "@type": "Organization", "name": "Latin Press, Inc.", "logo": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/lpi-eventos-online.png" } }, "author": { "@type": "Person", "name": "Ventas de Seguridad", "url": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15295-adobe-fixes-only-25-out-of-60-vulnerabilities-patch.html" } }
```
