ZDI-24-1200: Adobe Media Encoder AVI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Sep 10, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Media Encoder. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-39377.
Affected Software
1 affected component
Adobe Media Encoder
Event History
Sep 10, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1200?
ZDI-24-1200 has a high severity rating due to the potential for remote code execution.
2
How do I fix ZDI-24-1200?
To fix ZDI-24-1200, update to the latest version of Adobe Media Encoder.
3
What types of attacks can exploit ZDI-24-1200?
ZDI-24-1200 can be exploited through visiting a malicious webpage or opening a malicious file.
4
Is user interaction required for ZDI-24-1200 exploitation?
Yes, user interaction is required to exploit ZDI-24-1200.
5
Which software is affected by ZDI-24-1200?
ZDI-24-1200 affects Adobe Media Encoder 2022 installations.