ZDI-CAN-21709: Adobe After Effects MP4 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-47073

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
17 November 2023

Summary

Adobe After Effects versions 24.0.2 and earlier, along with version 23.6 and earlier, are vulnerable to an out-of-bounds write issue. This flaw could lead to arbitrary code execution in the context of the current user, necessitating user interaction for exploitation. Affected users may be compromised by opening maliciously crafted files, highlighting the need for vigilance and immediate updates to secure their systems.

Affected Version(s)

After Effects 0 <= 23.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.