
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN011
_____________________________________________________________________

DATE                : 12/01/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Windows, macOS running Adobe Illustrator versions
                            2020 prior to 9.0.2, 10.0.1, 11.0.0.

=====================================================================
https://helpx.adobe.com/security/products/illustrator/apsb21-02.html
_____________________________________________________________________


Security Updates Available for Adobe Illustrator | APSB21-02
Bulletin ID 	Date Published          Priority
ASPB21-02  	January 12, 2021       	3


Summary

Adobe has released an update for Adobe Illustrator 2020. This update
resolves a critical vulnerability that could lead to arbitrary code
execution in the context of current user.


Affected Versions

Product 	Version 	Platform
Illustrator 2020   25.0  and earlier versions   Windows


Solution

Adobe categorizes these updates with the following  priority ratings 
and recommends users update their installation to the newest version via
the Creative Cloud desktop app's update mechanism.  For more
information, please reference this help page.


Product          Version   Platform         Priority 	Availability
Illustrator 2020    25.1   Windows and macOS   3        Download Page


Vulnerability details

Vulnerability Category 	Vulnerability Impact 	Severity     CVE Numbers
Uncontrolled Search Path Element   Arbitrary code execution   	Critical
	CVE-2021-21007


Acknowledgments

Adobe would like to thank the following individuals and organizations
for reporting the relevant issues and for working with Adobe to help
protect our customers:    

    Hou JingYi (@hjy79425575) of Qihoo 360 CERT
    Yongjun Liu of nsfocus security team



=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================






