First published: Fri Sep 18 2020(Updated: )
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Media Encoder | <=14.3.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe Media Encoder vulnerability is CVE-2020-9745.
The severity of CVE-2020-9745 is high with a CVSS score of 7.1.
The affected software for CVE-2020-9745 is Adobe Media Encoder version 14.3.2 and earlier versions.
CVE-2020-9745 could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations.
Yes, user interaction is required to exploit CVE-2020-9745.
To fix the CVE-2020-9745 vulnerability, update Adobe Media Encoder to version 14.4 or later.
More information about CVE-2020-9745 can be found at the following link: [Adobe Security Bulletin APSB20-57](https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html).