CVE-2021-43747: Adobe Premiere Rush WAV File Memory Corruption Remote Code Execution
Published Dec 20, 2021
·Updated
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected Software
4 affected components
All of the following
Adobe Premiere Rush<=1.5.16
Microsoft Windows
Adobe Premiere Rush<=1.5.16
Microsoft Windows
Event History
Dec 20, 2021
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-43747.
2
What software versions are affected by this vulnerability?
Adobe Premiere Rush version 1.5.16 (and earlier) is affected.
3
What is the severity rating of CVE-2021-43747?
The severity rating is 7.8 (Critical).
4
How does this vulnerability occur?
This vulnerability occurs due to insecure handling of a malicious WAV file in Adobe Premiere Rush.
5
What is the potential impact of this vulnerability?
The potential impact is arbitrary code execution in the context of the current user.