CVE-2020-9745: Adobe Media Encoder PSD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Media Encoder vulnerability?
The vulnerability ID for this Adobe Media Encoder vulnerability is CVE-2020-9745.
What is the severity of CVE-2020-9745?
The severity of CVE-2020-9745 is high with a CVSS score of 7.1.
What is the affected software for CVE-2020-9745?
The affected software for CVE-2020-9745 is Adobe Media Encoder version 14.3.2 and earlier versions.
What is the risk of CVE-2020-9745?
CVE-2020-9745 could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations.
Is user interaction required to exploit CVE-2020-9745?
Yes, user interaction is required to exploit CVE-2020-9745.
How can I fix the CVE-2020-9745 vulnerability?
To fix the CVE-2020-9745 vulnerability, update Adobe Media Encoder to version 14.4 or later.
Where can I find more information about CVE-2020-9745?
More information about CVE-2020-9745 can be found at the following link: [Adobe Security Bulletin APSB20-57](https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html).