Impact
Adobe After Effects is affected by an out‑of‑bounds write that can lead to arbitrary code execution in the context of the user who opens a malicious file. The flaw is classified as CWE‑787 and allows an attacker to corrupt memory on the stack or heap. The vulnerability is triggered by opening a specially crafted file; no network or elevated privileges are required. Successful exploitation could give the attacker full control over the process, potentially enabling further lateral movement or persistence within the victim’s workload. The CVSS score of 7.8 reflects a high severity impact. The EPSS score of < 1 % indicates a low probability of widespread exploitation, and the vulnerability is not present in the CISA KEV catalog. Because a victim must voluntarily open a malicious file, user awareness and proper file handling remain the primary defense.
Affected Systems
Adobe After Effects is the affected product. No specific version ranges are disclosed by Adobe; the advisory states that the flaw exists in the current releases available at the time of publication.
Risk and Exploitability
A score of 7.8 indicates a high‑severity flaw, but the extremely low EPSS implies that widespread attacks are unlikely at present. No listing in the KEV catalog further reduces the threat pulse. The attack vector requires user interaction to open a malicious file, making social engineering and user education key mitigations.
OpenCVE Enrichment