CVE-2024-20771: Bridge 2024 MOV File parsing memory corruption
Published Apr 11, 2024
·Updated
Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
All of the following
Any of the following
Adobe Bridge<13.0.7
Adobe Bridge>=14.0.0<14.0.3
Any of the following
macOS
Microsoft Windows
Event History
Apr 11, 2024
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-20771?
CVE-2024-20771 has been classified as a moderate severity vulnerability due to the risk of sensitive memory disclosure.
2
How do I fix CVE-2024-20771?
To mitigate CVE-2024-20771, upgrade Adobe Bridge to version 13.0.7 or 14.0.3 or later.
3
What type of vulnerability is CVE-2024-20771?
CVE-2024-20771 is an out-of-bounds read vulnerability.
4
What could an attacker gain from exploiting CVE-2024-20771?
An attacker exploiting CVE-2024-20771 could potentially disclose sensitive information stored in memory.
5
Does CVE-2024-20771 require user interaction to exploit?
Yes, exploiting CVE-2024-20771 requires user interaction.