First published: Fri Mar 12 2021(Updated: )
Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Photoshop 2020 | <21.2.6 | |
Adobe Photoshop 2020 | >=22.0<22.3 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe Photoshop vulnerability is CVE-2021-21067.
The severity of CVE-2021-21067 is critical with a CVSS score of 7.8.
The affected software for CVE-2021-21067 is Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier).
CVE-2021-21067 allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
To fix CVE-2021-21067, update Adobe Photoshop to version 21.2.6 (for versions 21.2.5 and earlier) or update to version 22.3 (for versions 22.2 and earlier).