ZDI-CAN-21765: ZDI-23-1679: Adobe Premiere Pro M4A File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Premiere Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-47055.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21765?
ZDI-CAN-21765 has been assigned a CVSS rating indicating a significant risk due to the potential for remote code execution.
How do I fix ZDI-CAN-21765?
To mitigate ZDI-CAN-21765, update Adobe Premiere Pro to the latest version as recommended by Adobe.
Who is affected by ZDI-CAN-21765?
ZDI-CAN-21765 affects users of Adobe Premiere Pro, particularly those using older versions like CS4.
What type of exploitation is associated with ZDI-CAN-21765?
ZDI-CAN-21765 allows for remote code execution requiring user interaction with a malicious page or file.
Is user interaction required for ZDI-CAN-21765 to be exploited?
Yes, user interaction is necessary for ZDI-CAN-21765 as the target needs to visit a malicious page or open a harmful file.