CVE-2021-28579
Last modified
CVE-2021-28579 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants.. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Connect | < 11.2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28579?
How severe is CVE-2021-28579?
How do I fix CVE-2021-28579?
Are you affected by CVE-2021-28579?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
