First published: Tue Jan 12 2021(Updated: )
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Photoshop | <=22.1 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21006 is a heap buffer overflow vulnerability in Adobe Photoshop version 22.1 and earlier.
CVE-2021-21006 has a severity score of 8.6, indicating a high severity.
CVE-2021-21006 affects Adobe Photoshop version 22.1 and earlier, allowing arbitrary code execution if a specially crafted font file is opened.
No, Apple macOS is not vulnerable to CVE-2021-21006.
No, Microsoft Windows is not vulnerable to CVE-2021-21006.
Update to the latest version of Adobe Photoshop to mitigate CVE-2021-21006.