Adobe Premiere Pro Untrusted Search Path Vulnerability Could Lead to Arbitrary Code Execution
CVE-2024-34123

7HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
9 July 2024

Summary

Adobe Premiere Pro is vulnerable to an Untrusted Search Path issue that exposes the application to arbitrary code execution by an attacker. This vulnerability permits the insertion of a malicious file into the application’s search path, allowing the application to mistakenly execute it instead of the intended legitimate files. This method of exploitation necessitates user interaction, which escalates the attack complexity and highlights the critical importance of rigorous file validation and security practices within the application.

Affected Version(s)

Premiere Pro 0 <= 24.4.1

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.