← back
CVE-2021-21006highCWE-122

Heap buffer overflow when handling crafted font file could lead to arbitrary code execution

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 5.6%
exploitation probability
5.6%top 7% of all CVEs
observed exploitation
nono source reports it
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
Adobe · Photoshop