First published: Fri Sep 13 2024(Updated: )
Premiere Pro versions 24.5, 23.6.8 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe Premiere Pro CS4 | <23.6.9 | |
Adobe Premiere Pro CS4 | >=24.0<24.6 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39385 is a critical severity vulnerability affecting Adobe Premiere Pro that can lead to sensitive memory disclosure.
To fix CVE-2024-39385, update Adobe Premiere Pro to version 24.6 or later.
Premiere Pro versions 24.5, 23.6.8 and earlier are affected by CVE-2024-39385.
No, exploitation of CVE-2024-39385 requires user interaction.
CVE-2024-39385 allows attackers to potentially bypass mitigations such as ASLR.