CVE-2022-27784: Adobe After Effects Stack Buffer Overflow Could Lead To RCE
Published May 6, 2022
·Updated
Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in After Effects.
Affected Software
4 affected components
Adobe After Effects<=18.4.5
Adobe After Effects>=22.0<=22.2.1
macOS
Microsoft Windows
Event History
May 6, 2022
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-27784.
2
Which versions of Adobe After Effects are affected?
Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected.
3
What is the severity of CVE-2022-27784?
The severity of CVE-2022-27784 is critical with a CVSS score of 7.8.
4
What is the impact of CVE-2022-27784?
The vulnerability allows arbitrary code execution in the context of the current user.
5
How can the vulnerability be exploited?
Exploitation requires user interaction, such as opening a crafted file.