CVE-2021-40796: Adobe Premiere Pro Null Pointer Dereference Application denial-of-service
Published Mar 16, 2022
·Updated
Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
Adobe Premiere Pro<=15.4.1
macOS
Microsoft Windows
Remediation
Event History
Mar 16, 2022
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-40796.
2
What is the severity of CVE-2021-40796?
The severity of CVE-2021-40796 is medium (5.5).
3
What software versions are affected by CVE-2021-40796?
Adobe Premiere Pro 15.4.1 (and earlier) is affected by CVE-2021-40796.
4
What is the impact of CVE-2021-40796?
An unauthenticated attacker could achieve an application denial-of-service in the context of the current user.
5
Is Adobe Premiere Pro the only affected software by CVE-2021-40796?
Yes, Adobe Premiere Pro is the only affected software by CVE-2021-40796.