First published: Fri Aug 20 2021(Updated: )
Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Media Encoder | <=15.2 | |
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36016.
The title of the vulnerability is Adobe Media Encoder FLV File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability.
The severity of CVE-2021-36016 is medium with a severity value of 3.3.
Adobe Media Encoder version 15.2 is affected by CVE-2021-36016 on Windows OS.
CVE-2021-36016 can be exploited by a remote attacker when a user visits a malicious page or opens a malicious file.
Yes, Adobe has released a security bulletin with fixes for CVE-2021-36016. It is recommended to update to the latest version of Adobe Media Encoder.