CVE-2021-43018: Adobe Photoshop JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Sep 7, 2023
·Updated
Adobe Photoshop versions 23.0.2 and 22.5.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious JPG file.
Affected Software
4 affected components
Adobe Photoshop>=22.0<22.5.4
Adobe Photoshop>=23.0.0<23.0.2
macOS
Microsoft Windows
Event History
Sep 7, 2023
CVE Published
via MITRE·12:54 PM
Data Sourced
via MITRE·12:54 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Photoshop vulnerability?
The vulnerability ID for this Adobe Photoshop vulnerability is CVE-2021-43018.
2
What is the severity of CVE-2021-43018?
The severity of CVE-2021-43018 is high, with a CVSS score of 7.8.
3
Which versions of Adobe Photoshop are affected by CVE-2021-43018?
Adobe Photoshop versions 23.0.2 and 22.5.4 (and earlier) are affected by CVE-2021-43018.
4
What is the impact of CVE-2021-43018?
CVE-2021-43018 could result in arbitrary code execution in the context of the current user.
5
How can CVE-2021-43018 be exploited?
Exploitation of CVE-2021-43018 requires user interaction in that a victim must open a malicious JPG file.