CVE-2021-21098: Adobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote code execution
Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21098?
CVE-2021-21098 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2021-21098?
To fix CVE-2021-21098, update Adobe InDesign to version 16.1 or later.
Who is affected by CVE-2021-21098?
CVE-2021-21098 affects all users of Adobe InDesign version 16.0 and earlier.
Can CVE-2021-21098 be exploited remotely?
Yes, CVE-2021-21098 can be exploited remotely by an unauthenticated attacker.
What types of attacks can CVE-2021-21098 enable?
CVE-2021-21098 can enable attackers to achieve remote code execution in the context of the current user.