Bulletin ID
Security Updates Available for Adobe Digital Editions | APSB21-26
| 
                    
     | 
                
            
                
                    
     Date Published  | 
                
            
                
                    
     Priority  | 
                
            
        
|---|---|---|
| 
                    
     APSB20-26  | 
            
                
                
                    
     April 13, 2021     | 
            
                
                
                    
     3  | 
            
        
Summary
Adobe has released a security update for Adobe Digital Editions. This update resolves a critical vulnerability that could result in arbitrary file system write.
Affected product versions
| 
                    
     Product  | 
                
            
                
                    
     Version  | 
                
            
                
                    
     Platform  | 
                
            
        
|---|---|---|
| 
                    
     Adobe Digital Editions  | 
            
                
                
                    
     4.5.11.187245 and below     | 
            
                
                
                    
     MacOS  | 
            
        
Solution
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:
| 
                    
     Product  | 
                
            
                
                    
     Version  | 
                
            
                
                    
     Platform  | 
                
            
                
                    
     Priority  | 
                
            
                
                    
     Availability  | 
                
            
        
|---|---|---|---|---|
| 
                    
     Adobe Digital Editions  | 
            
                
                
                    
     4.5.11.187606  | 
            
                
                
                    
     MacOS  | 
            
                
                
                    
     3  | 
            
                
                
- Customers can download the update from the Adobe Digital Editions download page, or utilize the product’s update mechanism when prompted.
 - For more information, please refer the release notes.
 
Vulnerability details
| 
                    
     Vulnerability Category  | 
                
            
                
                    
     Vulnerability Impact  | 
                
            
                
                    
     Severity  | 
                
            
                
                    
     CVE Numbers  | 
                
            
        
|---|---|---|---|
| 
                    
     Privilege Escalation  | 
            
                
                
                    
     Arbitrary file system write  | 
            
                
                
                    
     Critical  | 
            
                
                
                    
     CVE-2021-21100  | 
            
        
Acknowledgments
Adobe would like to thank Qingyang Chen for reporting these issues and for working with Adobe to help protect our customers.