First published: Fri Aug 20 2021(Updated: )
Adobe Photoshop versions 21.2.9 (and earlier) and 22.4.2 (and earlier) are affected by an Improper input validation vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Photoshop | >=21.0.0<=21.2.9 | |
Adobe Photoshop | >=22.0.0<=22.4.2 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe Photoshop vulnerability is CVE-2021-36006.
Adobe Photoshop versions 21.2.9 (and earlier) and 22.4.2 (and earlier) are affected by this vulnerability.
The severity of CVE-2021-36006 vulnerability is medium with a CVSS score of 3.3.
This vulnerability allows an unauthenticated attacker to disclose arbitrary memory information in the context of the current user.
No, the vulnerability is not exploitable on Apple macOS or Microsoft Windows.
To fix the CVE-2021-36006 vulnerability in Adobe Photoshop, update to version 21.2.9 (or later) for Photoshop 21.x branch or version 22.4.2 (or later) for Photoshop 22.x branch.
You can find more information about this vulnerability on Adobe's security advisory page: https://helpx.adobe.com/security/products/photoshop/apsb21-63.html