First published: Fri Feb 17 2023(Updated: )
After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe After Effects | >=22.0.0<22.6.4 | |
Adobe After Effects | >=23.0.0<23.2.0 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability is an out-of-bounds read vulnerability that could lead to the disclosure of sensitive memory.
An attacker could bypass mitigations such as ASLR and potentially gain access to sensitive information.
Yes, exploitation of this issue requires user interaction.
After Effects versions between 23.0.0 and 23.1.0, and between 22.0.0 and 22.6.3 are affected by this vulnerability.
Apply the necessary security updates provided by Adobe to fix the vulnerability.