Adobe Responds to Customer Complaints, Will Patch Older Software

Adobe is changing its mind about not offering security updates to older versions of its Creative Suite software.

On Friday, the company reversed course. That decision came after many customers and security pros had expressed outrage over Adobe's decision to not issue security patches for CS5 and CS5.5.

The issue started last week when Adobe released a security bulletin announcing two vulnerabilities in Photoshop 5 and earlier versions, five vulnerabilities in Illustrator 5 and earlier versions, and one vulnerability in Flash Professional 5.5 and earlier versions. All of the vulnerabilities could be exploited on both Windows and Apple machines. At the time, Adobe indicated that people would have to upgrade to CS6 to get the issues fixed, and an interim patch wasn't merited.

"In looking at all aspects, including the vulnerabilities themselves and the threat landscape, the team did not believe the real-world risk to customers warranted an out-of-band release for the CS5 and CS5.5 versions to resolve these issues," an Adobe spokesperson explained.

Andrew Storms, director of security operations for security firm nCircle didn't see the logic in this, especially since products like Adobe Photoshop 5 are less than two years old.

"What the heck is wrong with Adobe?  It's not like Photoshop is a ninety-nine cent app, it costs hundreds of dollars to purchase," wrote Storms in a blog post.  "And the risk for the bug in Photoshop is high; the exploit code has already been made public. These security tactics make Adobe software look like ransom ware."

Users shared a similar sentiment. A Hacker News commenter questioned the legality of Adobe's actions and asked if there was any legal actions that could be taken.

"I own a copy of CS5.5 that was purchased 5 months ago," wrote user nkurz. "I'm already frustrated at the cost of the CS6 upgrade. Now Adobe is publicizing a critical vulnerability in their software for which the solution is me paying them for that upgrade. This feels a lot like extortion…."

Due to the backlash, Adobe on Friday said that it was reversing its decision not to supply a security update.

"We are in the process of resolving the vulnerabilities addressed in these Security Bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x (12.x) and Adobe Flash Professional CS5.x, and will update the respective Security Bulletins once the patches are available," according to an Adobe bulletin 



About the Author

Chris Paoli is the site producer for and


  • Microsoft Warns IT Pros on Windows Netlogon Fix Coming Next Month

    Microsoft on Thursday issued a reminder to organizations to ensure that their systems are properly patched for a "Critical"-rated Windows Netlogon vulnerability before next month's "update Tuesday" patch distribution arrives.

  • Microsoft Nudging Skype for Business Users to Teams

    Microsoft on Thursday announced some perks and prods for Skype for Business unified communications users, with the aim of moving them to the Microsoft Teams collaboration service instead.

  • How To Improve Windows 10's Sound and Video Quality

    Windows 10 comes with built-in tools that can help users get the most out of their sound and video hardware.

  • Microsoft Offers More 'Solorigate' Advice Using Microsoft 365 Defender Tools

    Microsoft issued yet another article with advice on how to use its Microsoft 365 Defender suite of tools to protect against "Solorigate" advanced persistent threat types of attacks in a Thursday announcement.

comments powered by Disqus