PT-2021-3927 · Adobe · After Effects
Published
2021-07-20
·
Updated
2022-10-27
·
CVE-2021-35995
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe After Effects version 18.2.1 and earlier
Description
The issue is caused by improper input validation when parsing a specially crafted file, allowing an unauthenticated attacker to disclose arbitrary memory information in the context of the current user. Exploitation requires user interaction, where a victim must open a malicious file. The vulnerability can also allow a remote attacker to execute arbitrary code using a specially crafted MP4 file.
Recommendations
For Adobe After Effects version 18.2.1 and earlier, update to a version that fixes the improper input validation vulnerability. As a temporary workaround, consider avoiding the use of MP4 files from untrusted sources until a patch is available. Restrict access to the file parsing functionality to minimize the risk of exploitation.
Fix
RCE
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
After Effects