Out-of-Bounds Read Vulnerability in Adobe After Effects
CVE-2025-43587

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 July 2025

What is CVE-2025-43587?

An out-of-bounds read vulnerability exists in Adobe After Effects versions 25.2, 24.6.6 and earlier, allowing potential disclosure of sensitive memory. This vulnerability necessitates user interaction, as it can only be exploited when a victim opens a specially crafted malicious file. Attackers might leverage this flaw to bypass memory protection measures such as ASLR, making it a notable risk for users.

Affected Version(s)

After Effects 0 <= 24.6.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.