First published: Wed Sep 01 2021(Updated: )
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit Software Development Kit | <=2020.1 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39847 is classified as a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2021-39847, upgrade to the latest version of Adobe XMP Toolkit SDK or apply security patches provided by Adobe.
CVE-2021-39847 can lead to arbitrary code execution, which may allow an attacker to take control of the affected system.
CVE-2021-39847 affects Adobe XMP Toolkit SDK versions up to and including 2020.1.
CVE-2021-39847 requires user interaction, as exploitation necessitates that the victim opens a specially crafted file.