CVE-2021-28580
Medium by Adobe file parsing buffer overflow vulnerability could lead to arbitrary code execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Medium by Adobe version 2.4.5.331 (and earlier) is affected by a buffer overflow vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Medium de Adobe versión 2.4.5.331 (y anteriores), está afectado por una vulnerabilidad de desbordamiento de búfer cuando se analiza un archivo diseñado. Un atacante no autenticado podría aprovechar esta vulnerabilidad para lograr una ejecución de código remota en el contexto del usuario actual. Es requerida una interacción del usuario para explotar este problema, ya que la víctima debe abrir un archivo malicioso
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-16 CVE Reserved
- 2021-09-08 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/medium/apsb21-34.html | 2021-09-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Medium Search vendor "Adobe" for product "Medium" | <= 2.4.5.331 Search vendor "Adobe" for product "Medium" and version " <= 2.4.5.331" | - |
Affected
| in | Oculus Search vendor "Oculus" | Rift Search vendor "Oculus" for product "Rift" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Medium Search vendor "Adobe" for product "Medium" | <= 2.4.5.331 Search vendor "Adobe" for product "Medium" and version " <= 2.4.5.331" | - |
Affected
| in | Oculus Search vendor "Oculus" | Rift S Search vendor "Oculus" for product "Rift S" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Medium Search vendor "Adobe" for product "Medium" | <= 2.4.5.331 Search vendor "Adobe" for product "Medium" and version " <= 2.4.5.331" | - |
Affected
| in | Oculus Search vendor "Oculus" | Touch Search vendor "Oculus" for product "Touch" | - | - |
Safe
|