PT-2021-5529 · Adobe · Media Encoder

Published

2021-12-14

·

Updated

2023-07-19

·

CVE-2021-43757

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Media Encoder versions 22.0, 15.4.2 and earlier
Description The issue is related to an out-of-bounds read vulnerability in Adobe Media Encoder when processing 3GP files. This could lead to the disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction, where a victim must open a malicious 3GP file.
Recommendations For Adobe Media Encoder versions 22.0, 15.4.2 and earlier, consider avoiding the use of 3GP files until a patch is available. As a temporary workaround, restrict the opening of 3GP files in Adobe Media Encoder to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2021-06379
CVE-2021-43757
ZDI-21-1576

Affected Products

Media Encoder