CVE-2021-28612: Adobe After Effects Out-of-bounds Read vulnerability
Adobe After Effects version 18.2 (and earlier) is affected by an Our-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information and cause a denial of service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-28612.
What is the severity rating of CVE-2021-28612?
The severity rating of CVE-2021-28612 is 7.1 (High).
Which software is affected by CVE-2021-28612?
Adobe After Effects version 18.2 (and earlier) is affected by CVE-2021-28612.
How can an attacker exploit CVE-2021-28612?
An unauthenticated attacker can exploit CVE-2021-28612 by leveraging the vulnerability to disclose sensitive memory information and cause a denial of service.
Is Microsoft Windows affected by CVE-2021-28612?
No, Microsoft Windows is not affected by CVE-2021-28612.
Where can I find more information about CVE-2021-28612?
More information about CVE-2021-28612 can be found at the following reference: [Adobe After Effects - APSB21-49](https://helpx.adobe.com/security/products/after_effects/apsb21-49.html)
What is the CWE ID for CVE-2021-28612?
The CWE ID for CVE-2021-28612 is CWE-125.