helpx.adobe.com
https://helpx.adobe.com/security/products/connect/apsb21-91.html CVE-2021-40719
CRITICAL
Adobe Connect Deserialization of Untrusted Data Remote Code Execution
Record summary
CVE-2021-40719 has a selected CVSS score of 9.8 (critical).
Description
Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialized on an Adobe Connect server. An attacker can leverage this to execute remote code execution on the server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ConnectBrowse Adobe / Connect | CVE List | Through 11.2.3 | affected |
| Through None | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-40719