PT-2021-4778 · Adobe · Bridge+1
Published
2021-10-26
·
Updated
2022-06-03
·
CVE-2021-42733
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Bridge version 11.1.1 and earlier
Adobe Prelude versions 10.1 and earlier
Description
The issue is related to improper input validation and a Null pointer dereference vulnerability when parsing specially crafted files. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service or execute arbitrary code in the context of the current user. Exploitation requires user interaction, where a victim must open a malicious file.
Recommendations
For Adobe Bridge version 11.1.1 and earlier, update to a version that addresses the Null pointer dereference vulnerability.
For Adobe Prelude versions 10.1 and earlier, update to a version that addresses the improper input validation vulnerability in the XDCAMSAM directory.
As a temporary workaround, consider restricting the opening of files from untrusted sources to minimize the risk of exploitation.
Fix
NULL Pointer Dereference
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bridge
Prelude