CVE-2021-40776: Adobe Lightroom Classic DLL Hijacking Local Privilege Escalation Vulnerability
Published Jun 15, 2022
·Updated
Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.
Affected Software
3 affected components
Adobe Lightroom<10.4
macOS
Microsoft Windows
Remediation
Event History
Jun 15, 2022
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-40776.
2
What is the affected software?
The affected software is Adobe Lightroom Classic 10.3 (and earlier).
3
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.1.
4
How can an attacker exploit this vulnerability?
An authenticated attacker can leverage this vulnerability to escalate privileges.
5
Is user interaction required to exploit this vulnerability?
Yes, user interaction is required before product installation to abuse this vulnerability.