CVE-2021-42727: Adobe Bridge Buffer Overflow Arbitrary code execution
Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42727?
CVE-2021-42727 is a stack overflow vulnerability in Adobe Bridge 11.1.1 (and earlier) that allows remote attackers to execute arbitrary code by tricking a user into opening a crafted file.
How severe is CVE-2021-42727?
The severity level of CVE-2021-42727 is considered critical, with a CVSS score of 7.8.
How does CVE-2021-42727 affect Adobe Bridge?
CVE-2021-42727 affects Adobe Bridge 11.1.1 (and earlier) by causing a stack overflow due to insecure handling of a crafted file.
Can arbitrary code be executed through CVE-2021-42727?
Yes, CVE-2021-42727 can potentially allow arbitrary code execution in the context of the current user, if a victim opens a crafted file in Adobe Bridge.
Is Microsoft Windows affected by CVE-2021-42727?
No, Microsoft Windows is not affected by CVE-2021-42727.
How can I fix CVE-2021-42727?
To fix CVE-2021-42727, it is recommended to update Adobe Bridge to version 11.2 or later, as described in the Adobe security advisory.