CVE-2021-42728: Adobe Bridge Buffer Overflow Arbitrary code execution
Published Mar 16, 2022
·Updated
Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge.
Affected Software
2 affected components
Adobe Bridge<=11.1.1
Microsoft Windows
Remediation
Event History
Mar 16, 2022
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-42728.
2
What is the severity of CVE-2021-42728?
The severity of CVE-2021-42728 is high with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2021-42728?
Adobe Bridge 11.1.1 (and earlier) is affected by CVE-2021-42728.
4
How can this vulnerability be exploited?
Exploitation of CVE-2021-42728 requires user interaction where a victim must open a crafted file in Adobe Bridge.
5
Is Microsoft Windows affected by CVE-2021-42728?
No, Adobe Bridge 11.1.1 (and earlier) is affected by CVE-2021-42728, not Microsoft Windows.