CVE-2023-47070: ZDI-CAN-21708: Adobe After Effects MP4 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Nov 17, 2023
·Updated
Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe After Effects>=23.0<=23.6
Adobe After Effects>=24.0<24.0.2
macOS
Microsoft Windows
Remediation
Event History
Nov 17, 2023
CVE Published
10:55 AM
Data Sourced
10:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-47070.
2
What is the severity of CVE-2023-47070?
The severity of CVE-2023-47070 is high with a CVSS score of 7.8.
3
Which software versions are affected by this vulnerability?
Adobe After Effects versions 24.0.2 and earlier, as well as versions 23.6 and earlier, are affected by this vulnerability.
4
How can this vulnerability be exploited?
Exploitation of this vulnerability requires user interaction, where a victim must open a malicious file in Adobe After Effects.
5
Is Microsoft Windows or Apple macOS affected by this vulnerability?
No, Microsoft Windows and Apple macOS are not affected by this vulnerability.