5.5
CVE-2024-20737
- EPSS 0.03%
- Veröffentlicht 10.04.2024 09:15:06
- Zuletzt bearbeitet 05.12.2024 15:09:48
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
Adobe After Effect 2024 RGB File parsing Memory Corruption Vulnerability
After Effects versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@adobe.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.