Out-of-bounds read vulnerability in Media Encoder could lead to code execution
CVE-2024-41871

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
13 September 2024

Summary

Adobe Media Encoder versions 24.5, 23.6.8, and earlier are susceptible to a vulnerability that allows for out-of-bounds reading of memory. This can expose sensitive information stored in memory, creating a risk for users when malicious files are opened. Exploitation of this vulnerability requires user interaction, meaning that a victim must inadvertently open a specially crafted file, which can compromise system integrity and security by allowing attackers to bypass common protections such as Address Space Layout Randomization (ASLR). Security recommendations emphasize avoiding opening untrusted files and updating to secure versions.

Affected Version(s)

Media Encoder 0 <= 23.6.8

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.