Bulletin ID
Security hotfix available for Adobe Captivate | APSB21-06
| 
                    
     | 
                
            
                
                    
     Date Published  | 
                
            
                
                    
     Priority  | 
                
            
        
|---|---|---|
| 
                    
     APSB21-06  | 
            
                
                
                    
     January 12, 2021  | 
            
                
                
                    
     3  | 
            
        
Summary
Adobe has released a security hotfix for Adobe Captivate. This hotfix addresses an important vulnerability. Successful exploitation could lead to privilege escalation in the context of the current user.
Affected versions
| 
                    
     Product  | 
                
            
                
                    
     Version  | 
                
            
                
                    
     Platform  | 
                
            
        
|---|---|---|
| 
                    
     Adobe Captivate 2019  | 
            
                
                
                    
     11.5.1.499 and earlier versions  | 
            
                
                
                    
     Windows  | 
            
        
Solution
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:
| 
                    
     Product  | 
                
            
                
                    
     Version  | 
                
            
                
                    
     Platform  | 
                
            
                
                    
     Priority  | 
                
            
                
                    
     Availability  | 
                
            
        
|---|---|---|---|---|
| 
                    
     Adobe Captivate 2019  | 
            
                
                
                    
     Hotfix  | 
            
                
                
                    
     Windows   | 
            
                
                
                    
     3  | 
            
                
                
1. Download Server.zip
2. Unzip the file
3. Replace the existing server.js file in “C:\Program Files\Adobe\Adobe Captivate 2019 x64\ns”
4. Restart Adobe Captivate
Vulnerability details
| 
                    
     Vulnerability Category  | 
                
            
                
                    
     Vulnerability Impact  | 
                
            
                
                    
     Severity  | 
                
            
                
                    
     CVE Number  | 
                
            
        
|---|---|---|---|
| 
                    
     Uncontrolled Search Path Element  | 
            
                
                
                    
     Privilege Escalation  | 
            
                
                
                    
     Important  | 
            
                
                
                    
     CVE-2021-21011  | 
            
        
Acknowledgments
Adobe would like to thank Xavier DANEST from Decathlon for reporting this issue and for working with Adobe to help protect our customers.