Impact
After Effects contains a stack‑buffer overflow that can lead to arbitrary code execution in the current user’s context when a crafted file is opened. The flaw is triggered by user interaction—specifically opening a malicious file; once triggered, the attacker can run code with the victim’s privileges, potentially compromising the application and, if the code executes with elevated permissions, the operating system.
Affected Systems
Adobe After Effects is the affected product. Versions of the application that are installed on macOS and Windows operating systems are vulnerable. All releases of After Effects that do not include the vendor’s update for this issue are at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity. The EPSS score of < 1% indicates that the likelihood of exploitation is very low at present, but the requirement for user interaction—opening a malicious file—reduces the probability of automated attacks. The vulnerability is not listed in the CISA KEV catalog, yet the potential for arbitrary code execution warrants close attention.
OpenCVE Enrichment