ZDI-19-907: Adobe Media Encoder CC MP4 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Media Encoder CC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of MP4 files. Crafted data in an MP4 file can trigger a read outside the bounds of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-19-907?
The severity of ZDI-19-907 is considered critical due to the potential for sensitive information disclosure.
How do I fix ZDI-19-907?
To fix ZDI-19-907, update to the latest version of Adobe Media Encoder that includes the security patch.
What type of attacks can exploit ZDI-19-907?
ZDI-19-907 can be exploited through social engineering, requiring user interaction with a malicious page or file.
Which versions of Adobe Media Encoder are affected by ZDI-19-907?
All affected versions of Adobe Media Encoder CC prior to the patch are vulnerable to ZDI-19-907.
What are the potential impacts of ZDI-19-907?
The potential impacts of ZDI-19-907 include unauthorized access to sensitive information from affected installations.