CVE-2021-42265: Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-42265?
CVE-2021-42265 is a vulnerability in Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) that allows for an out-of-bounds read and disclosure of sensitive memory.
How does CVE-2021-42265 affect Adobe Premiere Pro?
CVE-2021-42265 affects Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier), potentially leading to the disclosure of sensitive memory.
How can an attacker exploit CVE-2021-42265?
An attacker can exploit CVE-2021-42265 by leveraging the out-of-bounds read vulnerability to bypass mitigations like ASLR.
What is the severity of CVE-2021-42265?
The severity of CVE-2021-42265 is medium, with a severity value of 5.5.
How can I fix CVE-2021-42265?
To fix CVE-2021-42265, update Adobe Premiere Pro to versions 15.4.3 or 22.1.1, which include the necessary security patches.