← Back

CVE-2021-36006

nvd nist
Published: Aug 20, 2021Modified: Nov 21, 2024

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: psirt@adobe.com (Secondary)

Description

Adobe Photoshop versions 21.2.9 (and earlier) and 22.4.2 (and earlier) are affected by an Improper input validation vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected (2)

Products: Adobe: Photoshop
1 product
Photoshop
Configuration A
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Adobe
From 21.0.0 to 21.2.9
From 22.0.0 to 22.4.2
Running on/withPlatform Versions
Apple
Macos
All versions
Microsoft
Windows
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.