PT-2021-5969 · Adobe · Media Encoder

Published

2021-12-14

·

Updated

2023-07-19

·

CVE-2021-43759

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Media Encoder versions 22.0, 15.4.2 and earlier
Description The issue is related to an out-of-bounds read vulnerability in the Adobe Media Encoder application, which can lead to the disclosure of sensitive memory. This can be exploited by an attacker to bypass security mitigations such as Address Space Layout Randomization (ASLR). The exploitation of this issue requires user interaction, where a victim must open a specially crafted MP4 file.
Recommendations For Adobe Media Encoder versions 22.0, 15.4.2 and earlier, avoid opening malicious MP4 files until a patch is available. As a temporary workaround, consider restricting the use of MP4 file parsing functionality in Adobe Media Encoder until a fix is released. For all affected versions, ensure that users are cautious when opening MP4 files from untrusted sources to minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2022-00487
CVE-2021-43759
ZDI-21-1580

Affected Products

Media Encoder