CVE-2024-41859: After Effects | Out-of-bounds Write (CWE-787)
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41859?
CVE-2024-41859 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2024-41859?
To fix CVE-2024-41859, you should update Adobe After Effects to version 23.6.9 or later, or version 24.6 or later.
What versions of Adobe After Effects are affected by CVE-2024-41859?
CVE-2024-41859 affects Adobe After Effects versions 23.6.6, 24.5, and earlier.
What platforms are vulnerable to CVE-2024-41859?
CVE-2024-41859 impacts Adobe After Effects, which can run on both Apple macOS and Microsoft Windows.
Does exploiting CVE-2024-41859 require user interaction?
Yes, exploitation of CVE-2024-41859 requires user interaction by opening a malicious file.