CVE-2021-35990: Adobe Bridge JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Bridge version 11.0.2 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35990?
CVE-2021-35990 has been assigned a severity rating of critical due to its potential for arbitrary code execution.
How do I fix CVE-2021-35990?
To fix CVE-2021-35990, update Adobe Bridge to version 11.0.3 or later.
Who is affected by CVE-2021-35990?
CVE-2021-35990 affects users of Adobe Bridge up to and including version 11.0.2.
What is the impact of exploiting CVE-2021-35990?
Exploiting CVE-2021-35990 allows an unauthenticated attacker to execute arbitrary code in the context of the user running Adobe Bridge.
How can CVE-2021-35990 be exploited?
CVE-2021-35990 can be exploited by specially crafting a file that triggers the out-of-bounds write vulnerability when opened in Adobe Bridge.