CVE-2021-42533

HIGH

Adobe Bridge < 11.1.1 - Double Free

Title source: rule

Description

Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.

Scores

CVSS v3 7.8
EPSS 0.0472
EPSS Percentile 89.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (1)

adobe/bridge < 11.1.1

Timeline

Published Mar 16, 2022
Tracked Since Feb 18, 2026