ZDI-23-1667: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Media Encoder. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-47043.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1667?
ZDI-23-1667 has a significant severity rating due to its potential for remote code execution.
How do I fix ZDI-23-1667?
To mitigate ZDI-23-1667, update Adobe Media Encoder to the latest version provided by Adobe.
What impact does ZDI-23-1667 have on systems?
ZDI-23-1667 allows attackers to execute arbitrary code on affected systems, leading to potential data breaches or system compromise.
Is user interaction required for ZDI-23-1667 exploitation?
Yes, exploitation of ZDI-23-1667 requires user interaction, such as visiting a malicious page or opening a malicious file.
Which software is affected by ZDI-23-1667?
ZDI-23-1667 affects Adobe Media Encoder 2022 installations.