ZDI-24-1198: Adobe Premiere Pro AVI File Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Premiere Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2024-39385.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1198?
The severity of ZDI-24-1198 is classified as medium risk due to the potential for remote information disclosure.
How do I fix ZDI-24-1198?
To fix ZDI-24-1198, update Adobe Premiere Pro to the latest version provided by Adobe.
Who is affected by ZDI-24-1198?
Users of Adobe Premiere Pro, especially older versions like CS4, are affected by ZDI-24-1198.
What type of attacks can ZDI-24-1198 facilitate?
ZDI-24-1198 can facilitate remote attacks leading to the disclosure of sensitive information.
What is required to exploit ZDI-24-1198?
Exploitation of ZDI-24-1198 requires user interaction, such as visiting a malicious page or opening a malicious file.