CVE-2021-42529 is a stack-based buffer overflow vulnerability in Adobe XMP Toolkit SDK versions 2021.07 and earlier, affecting products like Adobe and Debian Linux distributions. This high-severity vulnerability (CVSS 7.8) requires user interaction, specifically opening a crafted file, to achieve arbitrary code execution with the privileges of the current user. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, there is some community discussion and media coverage, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021.07CPE matchmatch criteria | cpe:2.3:a:adobe:xmp_toolkit_software_development_kit:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
<= 2021.07CPE match | cpe:2.3:a:adobe:xmp_toolkit:*:*:*:*:*:java:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.