Impact
After Effects has a stack‑based buffer overflow that permits arbitrary code execution in the user’s context when a malicious file is opened. The flaw is triggered by opening a crafted file, requiring user interaction; once activated, the attacker can run code with the victim’s privileges, potentially compromising the application and, if the code executes with elevated permissions, the operating system.
Affected Systems
Adobe After Effects is the affected product. Versions of the application that are installed on macOS and Windows operating systems are vulnerable. All releases of After Effects that do not include the vendor’s update for this issue are at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity. The EPSS score of < 1% indicates that the likelihood of exploitation is very low at present, but the requirement for user interaction—opening a malicious file—reduces the probability of automated attacks. The vulnerability is not listed in the CISA KEV catalog, yet the potential for arbitrary code execution warrants close attention.
OpenCVE Enrichment