ZDI-CAN-21764: Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-47057

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
16 November 2023

Summary

Adobe Premiere Pro versions 24.0 and 23.6 are susceptible to an out-of-bounds write vulnerability, which allows for arbitrary code execution within the context of the current user. This vulnerability can be exploited when a user opens a specially crafted malicious file, leading to potential unauthorized actions on the user's system. It emphasizes the need for users to be cautious when handling files from untrusted sources.

Affected Version(s)

Premiere Pro 0 <= 24.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.