Impact
The vulnerability is an out-of-bounds write that allows an attacker to overwrite memory and execute arbitrary code while running in the user’s context. This can compromise confidentiality, integrity, and availability of the affected system by allowing a malicious user to run arbitrary programs, steal data, or disrupt operations. The weakness is classified as CWE-787. No specific product versions are listed, so the vulnerability is presumed to impact all releases of the software.
Affected Systems
Affected systems include Adobe After Effects for all versions in use at the time of the advisory. The advisory lists no specific version constraints; therefore the vulnerability applies to every release of After Effects that was available when Adobe issued APSB26‑78.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity with the potential for remote code execution. The EPSS score of less than 1% suggests that the probability is very low at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a malicious file, implying that a social‑engineering or phishing file into After Effects.
OpenCVE Enrichment