First published: Mon Dec 20 2021(Updated: )
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EXR file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Premiere Rush | <=1.5.16 | |
Microsoft Windows | ||
All of | ||
Adobe Premiere Rush | <=1.5.16 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-43021.
The affected software is Adobe Premiere Rush version 1.5.16 (and earlier).
CVE-2021-43021 has a severity rating of critical (7.8).
CVE-2021-43021 is a memory corruption vulnerability that occurs due to insecure handling of a malicious EXR file.
An attacker could potentially execute arbitrary code in the context of the current user by exploiting CVE-2021-43021.
Yes, user interaction is required to exploit CVE-2021-43021.
To fix CVE-2021-43021, update Adobe Premiere Rush to the latest version.
You can find more information about CVE-2021-43021 at the following link: https://helpx.adobe.com/security/products/premiere_rush/apsb21-101.html