ZDI-23-1782: Adobe After Effects AEP File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe After Effects. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-48635.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1782?
The severity of ZDI-23-1782 is considered critical due to its potential for remote information disclosure.
How do I fix ZDI-23-1782?
To mitigate ZDI-23-1782, update Adobe After Effects to the latest version released by Adobe.
What type of attack does ZDI-23-1782 enable?
ZDI-23-1782 enables remote attackers to disclose sensitive information from the affected installations.
Is user interaction required to exploit ZDI-23-1782?
Yes, user interaction is required, as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-23-1782?
The affected software for ZDI-23-1782 is Adobe After Effects 2025.