PT-2021-4976 · Adobe · Dreamweaver

Published

2021-02-09

·

Updated

2021-09-08

·

CVE-2021-21055

CVSS v3.1

6.2

Medium

VectorAV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Dreamweaver versions 21.0 and earlier Adobe Dreamweaver versions 20.2 and earlier
Description The issue is related to an untrusted search path vulnerability. This could allow an attacker with physical access to the system to replace certain configuration files and dynamic libraries that Dreamweaver references, potentially resulting in information disclosure. The vulnerability is associated with the use of an untrusted search path in the HTML editor.
Recommendations For Adobe Dreamweaver versions 21.0 and earlier, consider restricting access to configuration files and dynamic libraries to minimize the risk of exploitation. For Adobe Dreamweaver versions 20.2 and earlier, consider implementing additional security measures to protect against physical access to the system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05734
CVE-2021-21055

Affected Products

Dreamweaver