CVE-2021-36048: XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36048.
What is the severity of CVE-2021-36048?
CVE-2021-36048 has a severity rating of 7.8 (Critical).
What is the affected software?
The affected software is Adobe Xmp Toolkit Software Development Kit (version 2020.1 and earlier).
How does CVE-2021-36048 impact users?
CVE-2021-36048 can potentially result in arbitrary code execution in the context of the current user when a crafted file is opened. User interaction is required for exploitation.
Where can I find more information about CVE-2021-36048?
You can find more information about CVE-2021-36048 at the following references: 1. [Adobe Security Bulletin APSB21-65](https://helpx.adobe.com/security/products/xmpcore/apsb21-65.html) 2. [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2023/09/msg00032.html)