
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN014
_____________________________________________________________________

DATE                : 12/01/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):Windows running Adobe InCopy versions prior to 16.0.

=====================================================================
https://helpx.adobe.com/security/products/incopy/apsb21-05.html
_____________________________________________________________________

Security Update Available for Adobe InCopy | APSB21-05
Bulletin ID 	Date Published       Priority
APSB21-05 	January 12, 2021 	3


Summary

Adobe has released a security update for Adobe InCopy.  This update
addresses a critical vulnerability. Successful exploitation could lead
to arbitrary code execution in the context of the current
user.  


Affected versions

Product 	Affected version                Platform
Adobe InCopy   	15.1.3 and earlier versions   	Windows


Solution

Adobe categorizes these updates with the following priority rating and
recommends users update their software installations via the Creative
Cloud desktop app updater, or by navigating to the InCopy Help menu and
clicking "Updates." For more information, please reference this help
page.


Product      Updated version    Platform    Priority rating Availability
Adobe InCopy    16.0           Windows  	3          Release Note 

For managed environments, IT administrators can use the Creative Cloud
Packager to create deployment packages. Refer to this help page for more
information.


Vulnerability Details

Vulnerability Category 	Vulnerability Impact 	Severity    CVE Number
Uncontrolled search path element   Arbitrary code execution  Critical
CVE-2021-21010 


Acknowledgments

Adobe would like to thank Saurabh Kumar for reporting this issue and for
working with Adobe to help protect our customers. 


=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


