CVE-2021-40710: Adobe Premiere Pro 2021 SVG File Parsing Leads to Memory Corruption
Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40710?
CVE-2021-40710 is a memory corruption vulnerability in Adobe Premiere Pro, versions 15.4 and earlier, which allows arbitrary code execution.
How does CVE-2021-40710 impact Adobe Premiere Pro?
CVE-2021-40710 allows an attacker to execute arbitrary code in the context of the current user by exploiting a memory corruption vulnerability in Adobe Premiere Pro.
How can an attacker exploit CVE-2021-40710?
An attacker can exploit CVE-2021-40710 by convincing a user to open a specially crafted .svg file in Adobe Premiere Pro.
What is the severity of CVE-2021-40710?
The severity of CVE-2021-40710 is critical, with a CVSS score of 7.8.
Is Microsoft Windows affected by CVE-2021-40710?
No, Microsoft Windows is not affected by CVE-2021-40710.
How can I fix CVE-2021-40710 in Adobe Premiere Pro?
To fix CVE-2021-40710, users should update Adobe Premiere Pro to version 15.4.1 or later.
Where can I find more information about CVE-2021-40710?
More information about CVE-2021-40710 can be found on the Adobe security bulletin APSB21-67.
What are the Common Weakness Enumeration (CWE) identifiers associated with CVE-2021-40710?
The Common Weakness Enumeration (CWE) identifiers associated with CVE-2021-40710 are CWE-119 and CWE-788.