PT-2021-6264 · Adobe · Connect
Published
2021-06-08
·
Updated
2022-10-25
·
CVE-2021-28579
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Connect versions 11.2.1 and earlier
Description
The issue is related to improper access control in Adobe Connect, which can lead to the elevation of privileges. An attacker with
Learner permissions can exploit this to access the list of event participants. The vulnerability is associated with deficiencies in access control, allowing a remote attacker to increase their privileges.Recommendations
For Adobe Connect versions 11.2.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive features that can be exploited by users with
Learner permissions to minimize the risk of exploitation.Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Connect