PT-2021-4778 · Adobe · Bridge+1

Published

2021-10-26

·

Updated

2022-06-03

·

CVE-2021-42733

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Bridge version 11.1.1 and earlier Adobe Prelude versions 10.1 and earlier
Description The issue is related to improper input validation and a Null pointer dereference vulnerability when parsing specially crafted files. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service or execute arbitrary code in the context of the current user. Exploitation requires user interaction, where a victim must open a malicious file.
Recommendations For Adobe Bridge version 11.1.1 and earlier, update to a version that addresses the Null pointer dereference vulnerability. For Adobe Prelude versions 10.1 and earlier, update to a version that addresses the improper input validation vulnerability in the XDCAMSAM directory. As a temporary workaround, consider restricting the opening of files from untrusted sources to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05497
CVE-2021-42733

Affected Products

Bridge
Prelude