Out-of-bounds read vulnerability in Media Encoder could lead to code execution
CVE-2024-41871
7.8HIGH
Summary
Adobe Media Encoder versions 24.5, 23.6.8, and earlier are susceptible to a vulnerability that allows for out-of-bounds reading of memory. This can expose sensitive information stored in memory, creating a risk for users when malicious files are opened. Exploitation of this vulnerability requires user interaction, meaning that a victim must inadvertently open a specially crafted file, which can compromise system integrity and security by allowing attackers to bypass common protections such as Address Space Layout Randomization (ASLR). Security recommendations emphasize avoiding opening untrusted files and updating to secure versions.
Affected Version(s)
Media Encoder 0 <= 23.6.8
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved