CVE-2021-21099: Adobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote code execution
Published Jun 28, 2021
·Updated
Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
Adobe InDesign<=16.0
Apple macOS
Microsoft Windows
Event History
Jun 28, 2021
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21099?
CVE-2021-21099 has been rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2021-21099?
To fix CVE-2021-21099, update Adobe InDesign to version 16.1 or later.
3
What type of vulnerability is CVE-2021-21099?
CVE-2021-21099 is an Out-of-bounds Write vulnerability.
4
Who is affected by CVE-2021-21099?
CVE-2021-21099 affects Adobe InDesign version 16.0 and earlier.
5
Can CVE-2021-21099 be exploited by unauthenticated users?
Yes, CVE-2021-21099 can be exploited by unauthenticated attackers.