First published: Thu Sep 07 2023(Updated: )
Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Premiere Pro | <15.4.3 | |
Adobe Premiere Pro | >=22.0<22.1.1 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40790 is a Use-After-Free vulnerability in Adobe Premiere Pro, versions 22.0 and earlier, and 15.4.2 and earlier.
CVE-2021-40790 could lead to the disclosure of sensitive memory in affected versions of Adobe Premiere Pro.
Yes, versions 22.0 and earlier, and 15.4.2 and earlier are affected.
CVE-2021-40790 has a severity rating of 5.5, which is considered medium.
To mitigate the risk, it is recommended to update Adobe Premiere Pro to version 15.4.3 or 22.1.1 (or later) as soon as possible.