ZDI-CAN-21767: ZDI-23-1681: Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Premiere Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-47059.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21767?
ZDI-CAN-21767 is rated with a CVSS score, indicating a high severity vulnerability that can allow remote code execution.
How do I fix ZDI-CAN-21767?
To fix ZDI-CAN-21767, you should update Adobe Premiere Pro to the latest patched version provided by Adobe.
What type of attacks can exploit ZDI-CAN-21767?
ZDI-CAN-21767 can be exploited through remote code execution when a user visits a malicious webpage or opens a specially crafted file.
Is user interaction required for ZDI-CAN-21767?
Yes, user interaction is required for ZDI-CAN-21767, as the target must actively visit a malicious page or open a malicious file.
Which version of Adobe Premiere Pro is affected by ZDI-CAN-21767?
ZDI-CAN-21767 affects installations of Adobe Premiere Pro, including older versions such as Premiere Pro CS4.