ZDI-24-169: Adobe Audition AVI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Audition. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-20739.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-169?
The ZDI-24-169 vulnerability has a high severity rating according to the CVSS.
How do I fix ZDI-24-169?
To remediate ZDI-24-169, users should update Adobe Audition to the latest security patch provided by Adobe.
Who is affected by ZDI-24-169?
ZDI-24-169 affects installations of Adobe Audition that are not updated with the latest security fixes.
Can ZDI-24-169 be exploited without user interaction?
No, ZDI-24-169 requires user interaction, such as visiting a malicious page or opening a malicious file, to be exploited.
What type of attacks can ZDI-24-169 facilitate?
ZDI-24-169 can allow remote attackers to execute arbitrary code on the affected systems.