First published: Wed Sep 01 2021(Updated: )
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Xmp Toolkit Software Development Kit | <=2020.1 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36048.
CVE-2021-36048 has a severity rating of 7.8 (Critical).
The affected software is Adobe Xmp Toolkit Software Development Kit (version 2020.1 and earlier).
CVE-2021-36048 can potentially result in arbitrary code execution in the context of the current user when a crafted file is opened. User interaction is required for exploitation.
You can find more information about CVE-2021-36048 at the following references: 1. [Adobe Security Bulletin APSB21-65](https://helpx.adobe.com/security/products/xmpcore/apsb21-65.html) 2. [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2023/09/msg00032.html)