CVE-2021-28600: Adobe After Effects Out-of-bounds Read vulnerability could lead to sensitive information disclosure
Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28600?
The severity of CVE-2021-28600 is rated as important due to the potential for memory disclosure.
How do I fix CVE-2021-28600?
To fix CVE-2021-28600, update Adobe After Effects to version 18.3 or later.
Who is affected by CVE-2021-28600?
Users of Adobe After Effects version 18.2 and earlier are affected by CVE-2021-28600.
What type of vulnerability is CVE-2021-28600?
CVE-2021-28600 is classified as an Out-of-bounds Read vulnerability.
Can CVE-2021-28600 be exploited remotely?
CVE-2021-28600 requires local access, as it affects the current user's context.