CVE-2021-43023: Adobe Premiere Rush EPS/TIFF File Memory Corruption Remote Code Execution
Published Dec 20, 2021
·Updated
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EPS/TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected Software
4 affected components
All of the following
Adobe Premiere Rush<=1.5.16
Microsoft Windows
Adobe Premiere Rush<=1.5.16
Microsoft Windows
Event History
Dec 20, 2021
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-43023.
2
What is the severity level of CVE-2021-43023?
CVE-2021-43023 has a severity level of 7.8, which is considered critical.
3
What software versions are affected by CVE-2021-43023?
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by this vulnerability.
4
How can CVE-2021-43023 be exploited?
To exploit CVE-2021-43023, user interaction is required by opening a malicious EPS/TIFF file.
5
Is Microsoft Windows affected?
No, Microsoft Windows is not affected by CVE-2021-43023.