CVE-2021-28609: Adobe After Effects Out-of-bounds Read vulnerability could lead to sensitive information disclosure
Published Aug 24, 2021
·Updated
Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Adobe After Effects<=18.2
Microsoft Windows
Event History
Aug 24, 2021
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-28609.
2
What is the severity of CVE-2021-28609?
The severity of CVE-2021-28609 is medium with a CVSS score of 5.5.
3
Which software is affected by CVE-2021-28609?
Adobe After Effects version 18.2 (and earlier) is affected by CVE-2021-28609.
4
How does CVE-2021-28609 work?
CVE-2021-28609 is an out-of-bounds read vulnerability that occurs when parsing a specially crafted file in Adobe After Effects.
5
Is authentication required for exploiting CVE-2021-28609?
No, authentication is not required for exploiting CVE-2021-28609.