First published: Thu Sep 07 2023(Updated: )
Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Premiere Pro | <15.4.3 | |
Adobe Premiere Pro | >=22.0<22.1.1 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42265 is a vulnerability in Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) that allows for an out-of-bounds read and disclosure of sensitive memory.
CVE-2021-42265 affects Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier), potentially leading to the disclosure of sensitive memory.
An attacker can exploit CVE-2021-42265 by leveraging the out-of-bounds read vulnerability to bypass mitigations like ASLR.
The severity of CVE-2021-42265 is medium, with a severity value of 5.5.
To fix CVE-2021-42265, update Adobe Premiere Pro to versions 15.4.3 or 22.1.1, which include the necessary security patches.