CVE-2021-43021: Adobe Premiere Rush EXR File Memory Corruption Remote Code Execution
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EXR file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-43021.
What is the affected software?
The affected software is Adobe Premiere Rush version 1.5.16 (and earlier).
What is the severity of CVE-2021-43021?
CVE-2021-43021 has a severity rating of critical (7.8).
How does CVE-2021-43021 work?
CVE-2021-43021 is a memory corruption vulnerability that occurs due to insecure handling of a malicious EXR file.
What can an attacker do with CVE-2021-43021?
An attacker could potentially execute arbitrary code in the context of the current user by exploiting CVE-2021-43021.
Is user interaction required to exploit CVE-2021-43021?
Yes, user interaction is required to exploit CVE-2021-43021.
How can I fix CVE-2021-43021?
To fix CVE-2021-43021, update Adobe Premiere Rush to the latest version.
Where can I find more information about CVE-2021-43021?
You can find more information about CVE-2021-43021 at the following link: https://helpx.adobe.com/security/products/premiere_rush/apsb21-101.html