PT-2021-5109 · Adobe · Digital Editions

Published

2021-09-14

·

Updated

2021-10-01

·

CVE-2021-39826

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Digital Editions versions 4.5.11.187646 and earlier
Description The issue is related to an arbitrary command execution vulnerability. An authenticated attacker could leverage this vulnerability to execute arbitrary commands. User interaction is required to abuse this vulnerability, as a user must open a maliciously crafted .epub file. The vulnerability may also be exploited through a specially crafted link, allowing an attacker to execute arbitrary code.
Recommendations For Adobe Digital Editions versions 4.5.11.187646 and earlier, consider avoiding the use of .epub files from untrusted sources until a patch is available. As a temporary workaround, restrict the opening of .epub files to minimize the risk of exploitation.

Fix

XSS

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05898
CVE-2021-39826

Affected Products

Digital Editions