After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
History

Wed, 16 Oct 2024 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Mon, 16 Sep 2024 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121

Mon, 16 Sep 2024 13:00:00 +0000

Type Values Removed Values Added
Description After Effects versions 23.6.6, 24.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could lead to arbitrary file system write operations. An attacker could leverage this vulnerability to modify or corrupt files, potentially leading to a compromise of system integrity. Exploitation of this issue requires user interaction in that a victim must open a malicious file. After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title After Effects | Stack-based Buffer Overflow (CWE-121) After Effects | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125

Fri, 13 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Microsoft
Microsoft windows
Weaknesses CWE-119 CWE-787
CPEs cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Microsoft
Microsoft windows

Fri, 13 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe after Effects
Weaknesses CWE-119
CPEs cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe after Effects

Fri, 13 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 08:45:00 +0000

Type Values Removed Values Added
Description After Effects versions 23.6.6, 24.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could lead to arbitrary file system write operations. An attacker could leverage this vulnerability to modify or corrupt files, potentially leading to a compromise of system integrity. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title After Effects | Stack-based Buffer Overflow (CWE-121)
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2024-09-13T08:33:28.151Z

Updated: 2024-09-16T12:39:21.874Z

Reserved: 2024-07-22T17:16:40.940Z

Link: CVE-2024-41867

cve-icon Vulnrichment

Updated: 2024-09-13T14:07:13.617Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T09:15:10.620

Modified: 2024-10-16T13:31:42.040

Link: CVE-2024-41867

cve-icon Redhat

No data.