CVE-2021-40740: Adobe Audition Memory Corruption could lead to Arbitrary code execution
Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40740?
CVE-2021-40740 is a memory corruption vulnerability in Adobe Audition version 14.4 and earlier.
What is the severity of CVE-2021-40740?
The severity of CVE-2021-40740 is critical with a severity value of 7.8.
How does CVE-2021-40740 impact Adobe Audition?
CVE-2021-40740 allows for arbitrary code execution in the context of the current user when parsing a M4A file in Adobe Audition.
What software is affected by CVE-2021-40740?
Adobe Audition version 14.4 and earlier is affected by CVE-2021-40740.
Is Apple macOS or Microsoft Windows affected by CVE-2021-40740?
No, Apple macOS and Microsoft Windows are not affected by CVE-2021-40740.
How can this vulnerability be exploited?
Exploiting CVE-2021-40740 requires user interaction when processing a malicious M4A file in Adobe Audition.
How can I fix CVE-2021-40740?
Update Adobe Audition to version 14.4 or later to fix CVE-2021-40740.