Medium severity6.1NVD Advisory· Published Oct 13, 2021· Updated Jun 17, 2026
CVE-2021-40732
CVE-2021-40732
Description
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User interaction is required to exploit this vulnerability in that the victim will need to open a specially crafted MXF file.
Affected products
2- Range: <=2020.1
- Adobe/XMP Toolkitv5Range: unspecified
Patches
Vulnerability mechanics
References
3- helpx.adobe.com/security/products/xmpcore/apsb21-85.htmlnvdRelease NotesVendor Advisory
- lists.debian.org/debian-lts-announce/2023/09/msg00032.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/08/msg00003.htmlnvd
News mentions
0No linked articles in our index yet.