First published: Tue Jul 20 2021(Updated: )
Adobe Media Encoder version 15.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Media Encoder | <=15.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36015 is a memory corruption vulnerability in Adobe Media Encoder version 15.2 and earlier.
CVE-2021-36015 allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
CVE-2021-36015 has a severity level of critical with a CVSS score of 7.8.
An attacker can exploit CVE-2021-36015 by using a specially crafted file to trigger the memory corruption vulnerability.
No, Microsoft Windows is not affected by CVE-2021-36015.
More information about CVE-2021-36015 can be found at Adobe's security advisory: https://helpx.adobe.com/security/products/media-encoder/apsb21-43.html.
The Common Weakness Enumerations (CWE) associated with CVE-2021-36015 are CWE-787 (Out-of-bounds Write) and CWE-788 (Memory Corruption).