← volver
CVE-2021-39826

Adobe Digital Editions Command Execution Vulnerability

CVSS 8.6 HIGHEPSS 2.0%CWE-78
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.6EPSS 2.0%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
27 sep 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An authenticated attacker could leverage this vulnerability to execute arbitrary commands. User interaction is required to abuse this vulnerability in that a user must open a maliciously crafted .epub file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Productos afectados
Adobe · Digital Editions