Impact
An integer overflow or wraparound flaw exists in Adobe After Effects that allows a crafted file to corrupt internal counters and trigger execution of arbitrary code in the context of the user who opens the file.
Affected Systems
Adobe After Effects 25.6 and earlier are affected. The vulnerability can be triggered on Windows and macOS systems running the vulnerable versions of After Effects.
Risk and Exploitability
The flaw carries a CVSS score of 7.8, indicating high severity, but the EPSS score is below 1%, suggesting low exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires user interaction – a victim must open a malicious file – and thus depends on user behavior to launch the attack.
OpenCVE Enrichment