CVE-2021-36048

Severity
7.8HIGH
EPSS
0.5%
top 32.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateJun 16

Description

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5adobe/xmp_toolkitunspecified2020.1+1
Debianexempi< 2.5.2-1+deb11u1+3

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hj8w-jv52-fv86: XMP Toolkit SDK version 20202022-05-24
CVEList
XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution2021-09-01
OSV
CVE-2021-36048: XMP Toolkit SDK version 20202021-09-01

📋Vendor Advisories

2
Ubuntu
Exempi vulnerabilities2022-06-16
Debian
CVE-2021-36048: exempi - XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Va...2021
CVE-2021-36048 (HIGH CVSS 7.8) | XMP Toolkit SDK version 2020.1 (and | cvebase.io