CVE-2021-43758: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Jul 12, 2023
·Updated
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious MP4 file.
Affected Software
4 affected components
Adobe Media Encoder<15.4.3
Adobe Media Encoder=22.0
macOS
Microsoft Windows
Event History
Jul 12, 2023
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43758.
2
Which software versions are affected?
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected.
3
What is the impact of the vulnerability?
The vulnerability could lead to disclosure of sensitive memory and bypassing mitigations such as ASLR.
4
Is user interaction required for exploitation?
Yes, user interaction is required for exploitation of this vulnerability.
5
Are there any official references for this vulnerability?
Yes, you can refer to the Adobe advisory APSB21-118 for more information.