CVE-2023-48635: ZDI-CAN-22174: Adobe After Effects AEP File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48635?
CVE-2023-48635 is considered a medium severity vulnerability due to the potential for sensitive memory disclosure.
How do I fix CVE-2023-48635?
To fix CVE-2023-48635, update Adobe After Effects to version 24.0.4 or later, or 23.6.1 or later.
What versions of Adobe After Effects are affected by CVE-2023-48635?
Adobe After Effects versions 24.0.3 and earlier, and 23.6.0 and earlier are affected by CVE-2023-48635.
Can CVE-2023-48635 be exploited remotely?
CVE-2023-48635 requires local access, making remote exploitation unlikely without prior access.
What type of vulnerability is CVE-2023-48635?
CVE-2023-48635 is an out-of-bounds read vulnerability that could lead to the disclosure of sensitive memory.