First published: Wed Sep 01 2021(Updated: )
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit Software Development Kit | <=2020.1 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36050 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2021-36050, update to Adobe XMP Toolkit SDK version 2020.2 or later.
Exploitation of CVE-2021-36050 can lead to arbitrary code execution, allowing an attacker to execute commands on the affected system.
Affected software includes Adobe XMP Toolkit SDK version 2020.1 and earlier, as well as Debian Debian Linux version 10.0.
Yes, user interaction is required as the victim must open a crafted file for the exploitation of CVE-2021-36050 to occur.