CVE-2011-2131
published 2011-08-11CVE-2011-2131: Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of…
PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
22.20%
97.4th percentile
Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | creative_suite | — | — |
| adobe | creative_suite | — | — |
| adobe | photoshop | — | — |
| adobe | photoshop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition is a crafted GIF file with an invalid 'ushort ImageHeight' field value, causing memory corruption when opened in Adobe Photoshop CS5 (versions 12.0 / 12.1). Flag suspicious GIF files delivered to Photoshop users with malformed ImageHeight fields. ↗
- →Exploitation requires user interaction — the target must open a malicious GIF file. Monitor for GIF files opened by Photoshop processes (e.g. Photoshop.exe loading .gif) originating from untrusted/remote sources. ↗
- ·Affected versions are Adobe Photoshop 12.0 (CS5) and 12.1 (CS5.1) only. Detection and patching efforts should be scoped to these specific version strings. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://securityreason.com/securityalert/8347http://www.adobe.com/support/security/bulletins/apsb11-22.htmlhttp://www.us-cert.gov/cas/techalerts/TA11-222A.htmlhttp://securityreason.com/securityalert/8347http://www.adobe.com/support/security/bulletins/apsb11-22.htmlhttp://www.us-cert.gov/cas/techalerts/TA11-222A.html
2011-08-11
Published