First published: Wed Sep 08 2021(Updated: )
Medium by Adobe version 2.4.5.331 (and earlier) is affected by a buffer overflow vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Medium | <=2.4.5.331 | |
Oculus Rift | ||
Oculus Rift S | ||
Oculus Touch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28580 is a buffer overflow vulnerability in Medium by Adobe version 2.4.5.331 and earlier.
The severity of CVE-2021-28580 is critical with a severity value of 7.8.
CVE-2021-28580 affects Adobe Medium version 2.4.5.331 and earlier by allowing an unauthenticated attacker to achieve remote code execution in the context of the current user.
Exploitation of CVE-2021-28580 requires user interaction with a crafted file.
No, Oculus Rift and Oculus Touch are not affected by CVE-2021-28580.