First published: Wed Sep 01 2021(Updated: )
XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit Software Development Kit | <=2020.1 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36064 is considered a medium severity vulnerability due to the potential for arbitrary code execution through user interaction.
To fix CVE-2021-36064, users should upgrade to the latest version of Adobe XMP Toolkit that addresses the vulnerability.
CVE-2021-36064 could allow an attacker to execute arbitrary code on the victim's system if they open a specially crafted file.
CVE-2021-36064 affects Adobe XMP Toolkit version 2020.1 and earlier, as well as specific Debian versions.
Yes, exploitation of CVE-2021-36064 requires user interaction, such as opening a malicious file.