CVE-2021-36047
published 2021-09-01CVE-2021-36047: XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.72%
84.5th percentile
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | xmp_toolkit | unspecified – 2020.1 | — |
| adobe | xmp_toolkit_software_development_kit | <= 2020.1 | — |
| debian | debian_linux | — | — |
| debian | exempi | < exempi 2.6.0-1 (bookworm) | exempi 2.6.0-1 (bookworm) |
| exempi_project | exempi | >= 0 < 2.5.2-1+deb11u1 | 2.5.2-1+deb11u1 |
| exempi_project | exempi | >= 0 < 2.6.0-1 | 2.6.0-1 |
| exempi_project | exempi | >= 0 < 2.6.0-1 | 2.6.0-1 |
| exempi_project | exempi | >= 0 < 2.6.0-1 | 2.6.0-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g97q-g4qr-rcgw: XMP Toolkit SDK version 2020
ghsa_unreviewed·2022-05-24
CVE-2021-36047 [HIGH] CWE-20 GHSA-g97q-g4qr-rcgw: XMP Toolkit SDK version 2020
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
OSV
CVE-2021-36047: XMP Toolkit SDK version 2020
osv·2021-09-01·CVSS 7.8
CVE-2021-36047 [HIGH] CVE-2021-36047: XMP Toolkit SDK version 2020
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Ubuntu
Exempi vulnerabilities
vendor_ubuntu·2022-06-16
CVE-2021-36048 Exempi vulnerabilities
Title: Exempi vulnerabilities
Summary: Several security issues were fixed in Exempi.
It was discovered that Exempi incorrectly handled certain media files. If a
user or automated system were tricked into opening a specially crafted
file, a remote attacker could cause Exempi to stop responding or crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-36047: exempi - XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Va...
vendor_debian·2021·CVSS 7.8
CVE-2021-36047 [HIGH] CVE-2021-36047: exempi - XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Va...
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Scope: local
bookworm: resolved (fixed in 2.6.0-1)
bullseye: resolved (fixed in 2.5.2-1+deb11u1)
forky: resolved (fixed in 2.6.0-1)
sid: resolved (fixed in 2.6.0-1)
trixie: resolved (fixed in 2.6.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://helpx.adobe.com/security/products/xmpcore/apsb21-65.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00032.htmlhttps://helpx.adobe.com/security/products/xmpcore/apsb21-65.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2025/08/msg00003.html
2021-09-01
Published