PT-2021-5109 · Adobe · Digital Editions
Published
2021-09-14
·
Updated
2021-10-01
·
CVE-2021-39826
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Digital Editions versions 4.5.11.187646 and earlier
Description
The issue is related to an arbitrary command execution vulnerability. An authenticated attacker could leverage this vulnerability to execute arbitrary commands. User interaction is required to abuse this vulnerability, as a user must open a maliciously crafted .epub file. The vulnerability may also be exploited through a specially crafted link, allowing an attacker to execute arbitrary code.
Recommendations
For Adobe Digital Editions versions 4.5.11.187646 and earlier, consider avoiding the use of .epub files from untrusted sources until a patch is available. As a temporary workaround, restrict the opening of .epub files to minimize the risk of exploitation.
Fix
XSS
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Digital Editions