CVE-2025-27186: After Effects | Out-of-bounds Read (CWE-125)
After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27186?
CVE-2025-27186 is considered a critical vulnerability due to its potential to disclose sensitive memory.
How do I fix CVE-2025-27186?
To fix CVE-2025-27186, update Adobe After Effects to version 25.2 or later.
Which versions of Adobe After Effects are affected by CVE-2025-27186?
Adobe After Effects versions 25.1 and 24.6.4 and earlier are affected by CVE-2025-27186.
What can an attacker achieve by exploiting CVE-2025-27186?
An attacker can leverage CVE-2025-27186 to bypass mitigations like ASLR and potentially access sensitive memory.
Is user interaction required for CVE-2025-27186 to be exploited?
Yes, exploitation of CVE-2025-27186 requires user interaction.