CVE-2021-42532 is a stack-based buffer overflow vulnerability in Adobe XMP Toolkit SDK versions 2021.07 and earlier, affecting various products including Adobe and Debian Linux distributions. This high-severity vulnerability (CVSS 7.8) requires user interaction, specifically opening a crafted file, to achieve arbitrary code execution with the privileges of the current user. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, indicating awareness. The EPSS score is low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021.07CPE matchmatch criteria | cpe:2.3:a:adobe:xmp_toolkit_software_development_kit:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
<= 2021.07CPE match | cpe:2.3:a:adobe:xmp_toolkit:*:*:*:*:*:java:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.