CVE-2021-36056: XMP Toolkit SDK Heap-based Buffer Overflow Could Lead To Arbitrary Code Execution
Published Sep 1, 2021
·Updated
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Affected Software
2 affected components
Adobe Xmp Toolkit Software Development Kit<=2020.1
Debian Debian Linux=10.0
Remediation
Event History
Sep 1, 2021
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this buffer overflow vulnerability?
The vulnerability ID for this buffer overflow vulnerability is CVE-2021-36056.
2
What is the severity of CVE-2021-36056?
The severity of CVE-2021-36056 is critical with a CVSS score of 5.5.
3
What software is affected by CVE-2021-36056?
The XMP Toolkit SDK version 2020.1 (and earlier) is affected by CVE-2021-36056.
4
What is the potential impact of CVE-2021-36056?
CVE-2021-36056 can potentially result in arbitrary code execution in the context of the current user.
5
How can CVE-2021-36056 be exploited?
Exploitation of CVE-2021-36056 requires user interaction in that a victim must open a crafted file.