QID 375449

Date Published: 2021-04-22

QID 375449: Adobe Digital Editions Arbitrary File System Write Vulnerability (APSB21-26)

Adobe Digital Editions is an ebook reader software program from Adobe Systems built using Adobe Flash with support for acquiring, managing and reading eBooks, digital newspapers, and other digital publications. The software supports PDF, XHTML, and Flash-based content.

Affected Versions:
Adobe Digital Editions 4.5.11.187245 and below

QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of Digital Editions on MacOS

Successful exploit could allow attacker to arbitrary write file system

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.1 severity.
  • Solution

    Adobe has released a patch to fix this vulnerability. User are advised to upgrade to the latest version of software available. The latest version can be downloaded from APSB20-26

    CVEs related to QID 375449

    Software Advisories
    Advisory ID Software Component Link
    APSB20-26 URL Logo helpx.adobe.com/security/products/Digital-Editions/apsb21-26.html