PT-2021-4735 · Adobe+4 · Xmp Toolkit Sdk+4

Published

2021-08-17

·

Updated

2025-08-04

·

CVE-2021-36048

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XMP Toolkit SDK versions 2020.1 and earlier
Description The issue is related to insufficient input validation in the Adobe XMP-Toolkit-SDK, which can lead to arbitrary code execution in the context of the current user. This can be achieved by exploiting the vulnerability through a specially crafted file, requiring user interaction to open the file.
Recommendations For XMP Toolkit SDK versions 2020.1 and earlier, consider restricting the use of the software until a patch is available, and avoid opening crafted files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-05444
CVE-2021-36048
DLA-3585-1
DLA-4264-1
MGASA-2022-0236
USN-5483-1

Affected Products

Astra Linux
Debian
Linuxmint
Ubuntu
Xmp Toolkit Sdk