CVE-2021-40786 is a memory corruption vulnerability in Adobe Premiere Elements 20210809.daily.2242976 and earlier versions, affecting both Windows and macOS platforms. This flaw, rated High severity with a CVSS score of 7.8, can lead to arbitrary code execution in the context of the current user if a malicious file is opened. Exploitation requires user interaction, but the attack complexity is low. Currently, there is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2021.4CPE matchmatch criteria | cpe:2.3:a:adobe:premiere_elements:*:*:*:*:*:*:*:* | ||
<= 20210809.daily.2242976CPE match | cpe:2.3:a:adobe:premiere_elements:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.