Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-28623— Adobe Premiere Elements Privilege Escalation Vulnerability

EPSS 0.14% · P34
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-28623

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Adobe Premiere Elements Privilege Escalation Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在具有不安全权限的目录中创建临时文件
Source: NVD (National Vulnerability Database)
Vulnerability Title
Adobe Premiere Elements 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Adobe Premiere Elements是美国奥多比(Adobe)公司的一个视频编辑软件应用程序。它是Adobe Premiere Pro的缩小版本,专为新手编辑和消费者量身定制。 Adobe Premiere Elements 存在安全漏洞,该漏洞源于安装程序创建不安全的临时文件,本地攻击者可以在安装过程中覆盖临时文件,并提升对系统的权限。受影响的产品及版本如下:Premiere Elements: 13.1、14.1、2020.1、2020.2、2021.1
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
AdobePremiere unspecified ~ 5.2 -

II. Public POCs for CVE-2021-28623

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-28623

登录查看更多情报信息。

Same Patch Batch · Adobe · 2021-06-28 · 24 CVEs total

CVE-2021-211018.8 HIGHAdobe Illustrator TTF font parsing out-of-bounds write vulnerability could lead to remote
CVE-2021-285888.8 HIGHAdobe RoboHelp Server folderId Directory Traversal Remote Code Execution Vulnerability
CVE-2021-285628.8 HIGHAdobe Acrobat Reader use-after-free could lead to arbitrary code execution
CVE-2021-211028.8 HIGHAdobe Illustrator DOCX file parsing directory traversal vulnerability could lead to remote
CVE-2021-210908.8 HIGHAdobe InCopy DOCX file parsing directory traversal vulnerability could lead to remote code
CVE-2021-210998.8 HIGHAdobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote cod
CVE-2021-210988.8 HIGHAdobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote cod
CVE-2021-285708.3 HIGHAdobe After Effects uncontrolled search path element vulnerability could lead to remote co
CVE-2021-285837.5 HIGHMagento Commerce insecure storage of sensitive documentation
CVE-2021-210837.5 HIGHAdobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-
CVE-2021-210847.3 HIGHAdobe Experience Manager stored cross-site scripting vulnerability in resource resolver fa
CVE-2021-285566.9 MEDIUMMagento Commerce DOM-based cross-site scripting (XSS) could lead to arbitrary javascript e
CVE-2021-285636.5 MEDIUMMagento Commerce improper Authorization via the 'Create Customer' endpoint
CVE-2021-285845.4 MEDIUMMagento Commerce path traversal vulnerability in child theme store creation
CVE-2021-285855.3 MEDIUMMagento Commerce improper input validation in customer customer webapi
CVE-2021-285754.3 MEDIUMAdobe Animate out-of-bounds read vulnerability could lead to information exposure
CVE-2021-285794.3 MEDIUMAdobe Connect improper access control could lead to privilege escalation
CVE-2021-285744.3 MEDIUMAdobe Animate out-of-bounds read vulnerability could lead to information exposure
CVE-2021-285764.3 MEDIUMAdobe Animate out-of-bounds read vulnerability could lead to information exposure
CVE-2021-285734.3 MEDIUMAdobe Animate out-of-bounds read vulnerability could lead to information exposure

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-28623

No comments yet


Leave a comment