ZDI-24-1197: Adobe Audition AVI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Audition. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-39378.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1197?
The CVSS rating for ZDI-24-1197 indicates a critical severity level due to the potential for remote code execution.
How do I fix ZDI-24-1197?
To fix ZDI-24-1197, update Adobe Audition to the latest version provided by Adobe that addresses this vulnerability.
Who is affected by ZDI-24-1197?
Adobe Audition users who have not updated to the latest security patches are affected by ZDI-24-1197.
What type of attack does ZDI-24-1197 facilitate?
ZDI-24-1197 facilitates remote code execution attacks that require user interaction, such as visiting a malicious page or opening a harmful file.
What should I do if I suspect exploitation of ZDI-24-1197?
If you suspect exploitation of ZDI-24-1197, disconnect the affected system from the network and apply the necessary updates immediately.