CVE-2021-42531 is a stack-based buffer overflow vulnerability in Adobe XMP Toolkit SDK version 2021.07 and earlier, affecting Adobe and Debian Linux distributions. This high-severity vulnerability (CVSS 7.8) requires user interaction, specifically opening a crafted file, to achieve arbitrary code execution with the privileges of the current user. While not currently listed in CISA's KEV catalog, its FAUCET Risk Score of 60/100 and community discussion exceeding 90% of all CVEs indicate significant concern. There are no known public exploits or Metasploit/Nuclei modules available, but media coverage suggests awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021.07CPE matchmatch criteria | cpe:2.3:a:adobe:xmp_toolkit_software_development_kit:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
<= 2021.07CPE match | cpe:2.3:a:adobe:xmp_toolkit:*:*:*:*:*:java:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.