PT-2021-5102 · Adobe · Bridge

Published

2021-04-13

·

Updated

2022-10-21

·

CVE-2021-21096

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Adobe Bridge versions 10.1.1 and earlier Adobe Bridge versions 11.0.1 and earlier
Description The issue is related to an Improper Authorization vulnerability in the Genuine Software Service of Adobe Bridge. A low-privileged attacker could exploit this to achieve application denial-of-service in the context of the current user. Exploitation does not require user interaction.
Recommendations For Adobe Bridge versions 10.1.1 and earlier, update to a version later than 10.1.1 to resolve the issue. For Adobe Bridge versions 11.0.1 and earlier, update to a version later than 11.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the Genuine Software Service to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-05887
CVE-2021-21096
ZDI-21-417

Affected Products

Bridge