PT-2021-5098 · Adobe · Captivate

Published

2021-08-17

·

Updated

2022-10-27

·

CVE-2021-36002

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Captivate versions 11.5.5 and earlier
Description The issue is related to the creation of temporary files with incorrect permissions, which could allow an attacker to escalate privileges in the context of the current user. This can be achieved by planting a malicious file in a specific location on the victim's machine. Exploitation requires user interaction, as the victim must launch the Captivate Installer.
Recommendations For Adobe Captivate versions 11.5.5 and earlier, consider restricting access to the temporary file directory to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid launching the Captivate Installer from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2021-05883
CVE-2021-36002

Affected Products

Captivate