PT-2021-4170 · Adobe · Dimension

Published

2021-07-13

·

Updated

2021-08-30

·

CVE-2021-28595

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Dimension versions 3.4 and earlier
Description The issue is related to an Uncontrolled Search Path Element element. An unauthenticated attacker could leverage this to achieve arbitrary code execution in the context of the current user. Exploitation requires user interaction, where a victim must open a malicious file.
Recommendations For Adobe Dimension version 3.4 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04765
CVE-2021-28595

Affected Products

Dimension