Adobe Security Bulletin
Security update available for Adobe Dreamweaver | APSB19-21
Bulletin ID Date Published Priority
APSB19-21 April 09, 2019 3

Summary

Adobe has released a security update for Adobe Dreamweaver.  This update resolves a vulnerability rated moderate related to the use of the Server Message Block (SMB) protocol when handling UNC paths in Dreamweaver. 

Affected Versions

Product Affected Versions Platform
Adobe Dreamweaver

19.0 and earlier versions

18.2 and earlier versions

Windows and macOS

Solution

Adobe categorizes this update with the following priority rating and recommends users update their software installations via the Creative Cloud desktop app updater, or by navigating to the Dreamweaver Help menu and clicking "Updates." For more information, please reference this help page.

Product Updated Version Platform Priority rating
Adobe Dreamweaver 19.1 Windows and macOS 3
18.2.1 Windows and macOS 3

Note:

For managed environments, IT administrators can use the Creative Cloud Packager to create deployment packages. Refer to this help page for more information on the Creative Cloud Packager. 

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVE Numbers
Insecure protocol implementation Sensitive data disclosure if SMB request is subject to a relay attack Moderate CVE-2019-7097

Revisions

August 13, 2019: The latest release of Adobe Dreamweaver 18.2.1 resolves this vulnerability in Adobe Dreamweaver CC 18.2 release. Affected and solution sections are updated with the version numbers.