CVE-2021-39821: Adobe InDesign TIF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published Sep 29, 2021
·Updated
Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious TIF file.
Affected Software
8 affected components
Adobe InDesign<=16.3.2
Apple macOS
Adobe InDesign<=16.3
Microsoft Windows
All of the following
Adobe InDesign<=16.3.2
Apple macOS
All of the following
Adobe InDesign<=16.3
Microsoft Windows
Event History
Sep 29, 2021
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-39821?
CVE-2021-39821 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2021-39821?
To mitigate CVE-2021-39821, users should update Adobe InDesign to version 16.3.2 or later.
3
What versions of Adobe InDesign are affected by CVE-2021-39821?
CVE-2021-39821 affects Adobe InDesign versions 16.3 and earlier, including version 16.3.1.
4
What type of vulnerability is CVE-2021-39821?
CVE-2021-39821 is classified as an out-of-bounds read vulnerability.
5
What user interaction is needed for CVE-2021-39821 exploitation?
Exploitation of CVE-2021-39821 requires the victim to open a specially crafted file.