PT-2021-4210 · Adobe · Incopy

Published

2021-09-14

·

Updated

2022-04-25

·

CVE-2021-39818

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe InCopy versions 11.1 and earlier
Description The issue is related to a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Recommendations For Adobe InCopy versions 11.1 and earlier, update to a version that fixes the memory corruption vulnerability to prevent arbitrary code execution. As a temporary workaround, consider avoiding the use of malicious TIFF files until a patch is available. Restrict user interaction with potentially malicious files to minimize the risk of exploitation.

Fix

Buffer Overflow

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04811
CVE-2021-39818

Affected Products

Incopy