First published: Thu Jul 16 2020(Updated: )
Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Media Encoder | <=14.2 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9649 is a remote code execution vulnerability in Adobe Media Encoder that allows attackers to execute arbitrary code on affected installations.
CVE-2020-9649 is exploited when a user visits a malicious page or opens a malicious file, triggering an out-of-bounds read vulnerability in the processing of 3GP files.
CVE-2020-9649 has a severity rating of 7.8 out of 10, which is considered high.
To fix CVE-2020-9649, users should apply the necessary security updates provided by Adobe.
More information about CVE-2020-9649 can be found on the Adobe Security Bulletin (APSB20-36) and Zero Day Initiative advisories.