CVE-2021-44189: Adobe After Effects JPEG2000 Parsing Use-After-Free Information Disclosure Vulnerability
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-44189.
Which versions of Adobe After Effects are affected by this vulnerability?
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected.
What is the impact of this vulnerability?
This vulnerability could lead to disclosure of sensitive memory and allow bypassing of mitigations such as ASLR.
How can an attacker exploit this vulnerability?
Exploitation of this vulnerability requires user interaction.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: [Adobe Security Bulletin APSB21-115](https://helpx.adobe.com/security/products/after_effects/apsb21-115.html).