CVE-2021-28603: Adobe After Effects heap corruption vulnerability could lead to arbitrary code execution
Adobe After Effects version 18.2 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Adobe After Effects?
The vulnerability ID for Adobe After Effects is CVE-2021-28603.
What is the severity rating for CVE-2021-28603?
CVE-2021-28603 has a severity rating of 7.8 (Critical).
Which versions of Adobe After Effects are affected?
Adobe After Effects version 18.2 (and earlier) is affected.
What is the impact of the vulnerability?
The vulnerability allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
How can I fix CVE-2021-28603?
Apply the necessary security updates provided by Adobe to fix CVE-2021-28603.