CVE-2023-47055: ZDI-CAN-21765: Adobe Premiere Pro M4A File Parsing Use-After-Free Remote Code Execution Vulnerability
Published Nov 16, 2023
·Updated
Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Premiere Pro<=23.6
Adobe Premiere Pro=24.0
macOS
Microsoft Windows
Event History
Nov 16, 2023
CVE Published
04:16 PM
Data Sourced
04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Premiere Pro vulnerability?
The vulnerability ID is CVE-2023-47055.
2
Which versions of Adobe Premiere Pro are affected by this vulnerability?
Adobe Premiere Pro versions 24.0 (and earlier) and 23.6 (and earlier) are affected.
3
What is the severity of CVE-2023-47055?
The severity of CVE-2023-47055 is rated as high, with a severity value of 7.8.
4
What can an attacker achieve by exploiting this vulnerability?
An attacker can achieve arbitrary code execution in the context of the current user.
5
Is user interaction required to exploit this vulnerability?
Yes, exploitation of this vulnerability requires user interaction in that a victim must open a malicious file.