CVE-2021-40776
CVE-2021-40776 is a medium-severity vulnerability in Adobe Lightroom with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-379.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v2: 6.6
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-379
- Affected product: Adobe Lightroom
- Published:
- Last modified:
Description
Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.
Frequently asked questions
- What is CVE-2021-40776?
- Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.
- How severe is CVE-2021-40776?
- CVE-2021-40776 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over physical access with low attack complexity, requires high privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2021-40776 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-40776?
- CVE-2021-40776 affects Adobe Lightroom. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-40776?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-40776 published?
- CVE-2021-40776 was published on 2022-06-15 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
More vulnerabilities in Adobe Lightroom
- CVE-2026-48441 — High (CVSS 8.6): Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')…
- CVE-2026-48397 — High (CVSS 8.6): Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code…
- CVE-2026-48410 — High (CVSS 7.8): Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in…
- CVE-2026-48409 — High (CVSS 7.8): Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in…
- CVE-2026-48408 — High (CVSS 7.8): Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in…
- CVE-2026-48407 — High (CVSS 7.8): Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in…
All CVEs affecting Adobe Lightroom →
Other CWE-379 vulnerabilities
- CVE-2024-9950 — High (CVSS 7.8): A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify…
- CVE-2024-9500 — High (CVSS 7.8): A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer…
- CVE-2023-6080 — High (CVSS 7.8): Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation…
- CVE-2023-3181 — High (CVSS 7.8): The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at…
- CVE-2023-37243 — High (CVSS 7.8): The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM…
- CVE-2023-26396 — High (CVSS 7.8): Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Creation of…