PT-2021-5685 · Adobe · Premiere Rush

Published

2021-12-14

·

Updated

2025-08-05

·

CVE-2021-43030

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Premiere Rush versions 1.5.16 and earlier
Description The issue is related to the parsing of MP4 files and results from the lack of proper initialization of memory prior to accessing it. This allows remote attackers to disclose arbitrary data on affected installations. User interaction is required to exploit this vulnerability, where the target must visit a malicious page or open a malicious file.
Recommendations For Adobe Premiere Rush versions 1.5.16 and earlier, consider avoiding the use of MP4 file parsing until a patch is available. As a temporary workaround, restrict the opening of MP4 files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

BDU:2022-00124
CVE-2021-43030
ZDI-21-1587

Affected Products

Premiere Rush