CVE-2021-40790: Adobe Premiere Pro MOV File Parsing Use-After-Free Information Disclosure Vulnerability
Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-40790?
CVE-2021-40790 is a Use-After-Free vulnerability in Adobe Premiere Pro, versions 22.0 and earlier, and 15.4.2 and earlier.
How does CVE-2021-40790 impact Adobe Premiere Pro?
CVE-2021-40790 could lead to the disclosure of sensitive memory in affected versions of Adobe Premiere Pro.
Are all versions of Adobe Premiere Pro affected by CVE-2021-40790?
Yes, versions 22.0 and earlier, and 15.4.2 and earlier are affected.
What is the severity of CVE-2021-40790?
CVE-2021-40790 has a severity rating of 5.5, which is considered medium.
How can I mitigate the risk of CVE-2021-40790?
To mitigate the risk, it is recommended to update Adobe Premiere Pro to version 15.4.3 or 22.1.1 (or later) as soon as possible.