Stack-based Buffer Overflow Vulnerability Affects Media Encoder Versions
CVE-2024-20772
7.8HIGH
Summary
The vulnerability in Adobe Media Encoder is characterized by a stack-based buffer overflow that poses a risk of arbitrary code execution. This flaw specifically affects versions 24.2.1 and 23.6.4, along with earlier releases. Exploitation of this vulnerability necessitates user interaction, as the user must open a crafted file designed to trigger the overflow. This condition emphasizes the importance of cautious file handling and highlights the need for timely updates to protect systems from potential exploitation.
Affected Version(s)
Media Encoder 0 <= 23.6.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved