CVE-2021-21104
published 2021-09-08CVE-2021-21104: Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated…
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.87%
91.0th percentile
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | illustrator | <= 25.2 | — |
| adobe | illustrator | unspecified – 25.2 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Fortinet
FortiGuard Labs Discovers Multiple Critical Zero Day Vulnerabilities in Adobe Illustrator
blogs_fortinet·2021-05-12·CVSS 4.3
[MEDIUM] FortiGuard Labs Discovers Multiple Critical Zero Day Vulnerabilities in Adobe Illustrator
FORTIGUARD LABS THREAT RESEARCH
FortiGuard Labs Discovers Multiple Critical Zero Day Vulnerabilities in Adobe Illustrator
By Kushal Arvind Shah | May 12, 2021
FortiGuard Labs Threat Research Report
Affected platforms: Windows
Impacted parties: Users of Adobe Illustrator 2021, versions 25.2 and earlier
Impact: Multiple Vulnerabilities leading to Arbitrary Code Execution
Severity level: Critical
Earlier this year, in February of 2021, I discovered and reported multiple critical zero-day vulnerabilities in Adobe Illustrator to Adobe, Inc. This past Tuesday, May 11, 2021, Adobe released several security patches that fixed these vulnerabilities. They are identified as CVE-2021-21103, CVE-2021-21104, and CVE-2021-21105. All these vulnerabilities have different root causes related to a varie
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
2021-09-08
Published