CVE-2022-24096: Adobe After Effects Heap-based Buffer Overflow Arbitrary code execution
Published Mar 11, 2022
·Updated
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe After Effects>=18.0<18.4.5
Adobe After Effects>=22.0<22.2.1
macOS
Microsoft Windows
Remediation
Event History
Mar 11, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24096.
2
What is the severity of CVE-2022-24096?
The severity of CVE-2022-24096 is critical, with a CVSS score of 7.8.
3
Which versions of Adobe After Effects are affected by CVE-2022-24096?
Adobe After Effects versions 18.4.4 (and earlier) and 22.2 (and earlier) are affected.
4
What is the impact of CVE-2022-24096?
CVE-2022-24096 could result in arbitrary code execution in the context of the current user.
5
How can CVE-2022-24096 be exploited?
Exploitation of CVE-2022-24096 requires user interaction, where a victim must open a malicious file.