CVE-2024-41872: Media Encoder | Out-of-bounds Read (CWE-125)
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41872?
CVE-2024-41872 is classified as a high severity vulnerability due to the potential for sensitive memory disclosure.
How do I fix CVE-2024-41872?
To mitigate CVE-2024-41872, upgrade Adobe Media Encoder to version 24.6 or later or to version 23.6.9 or later.
What are the affected versions of Adobe Media Encoder in CVE-2024-41872?
Affected versions include Adobe Media Encoder 24.5, 23.6.8, and earlier.
Can CVE-2024-41872 be exploited without user interaction?
Exploitation of CVE-2024-41872 requires user interaction, making it contingent on user actions.
Which operating systems are impacted by CVE-2024-41872?
CVE-2024-41872 affects Adobe Media Encoder on platforms like macOS and Windows, but not the operating systems themselves.