Description
Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Media Encoder contains a stack-based buffer overflow that allows an attacker to execute arbitrary code when a user opens a crafted media file. The vulnerability can lead to execution of malicious code with the permissions of the current user, compromising confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is Adobe Media Encoder. No specific version numbers are provided in the advisory, so all releases of Adobe Media Encoder might be impacted until an official fix is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, yet the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and requires user interaction – the victim must open a malicious file – which limits the attack surface. Nonetheless, the potential impact remains significant if an attacker successfully tricks a user into opening the file.

Generated by OpenCVE AI on July 31, 2026 at 05:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Adobe Security Update for Media Encoder as detailed in the official Adobe advisory.
  • Restrict the automatic opening of unknown media files and disable any features that auto‑run scripts or applications from media content.
  • Provide user training and awareness so that users recognize and avoid opening suspicious media files.

Generated by OpenCVE AI on July 31, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe media Encoder
Vendors & Products Adobe
Adobe media Encoder

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Media Encoder | Stack-based Buffer Overflow (CWE-121)
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Media Encoder
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:36:44.052Z

Reserved: 2026-05-20T15:50:31.365Z

Link: CVE-2026-47971

cve-icon Vulnrichment

Updated: 2026-07-15T10:36:38.911Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow