CVE-2021-28624: Adobe Bridge SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Adobe Bridge version 11.0.2 (and earlier) are affected by a Heap-based Buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28624?
CVE-2021-28624 has been assigned a critical severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2021-28624?
To mitigate CVE-2021-28624, upgrade Adobe Bridge to version 11.0.3 or later.
Who is affected by CVE-2021-28624?
Users of Adobe Bridge version 11.0.2 and earlier on any supported operating system are affected by CVE-2021-28624.
What can an attacker achieve by exploiting CVE-2021-28624?
Exploitation of CVE-2021-28624 can allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
Does CVE-2021-28624 require user interaction to exploit?
Yes, exploiting CVE-2021-28624 requires some form of user interaction to trigger the vulnerability.