ZDI-CAN-21792: ZDI-23-1682: Adobe Premiere Pro MP4 File Uninitialized Variable Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Premiere Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-47060.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21792?
The severity of ZDI-CAN-21792 is rated as medium due to the requirement for user interaction for exploitation.
How do I fix ZDI-CAN-21792?
To fix ZDI-CAN-21792, users should update Adobe Premiere Pro to the latest version provided by Adobe.
What type of information can be disclosed through ZDI-CAN-21792?
ZDI-CAN-21792 can lead to the disclosure of sensitive information on affected installations of Adobe Premiere Pro.
What conditions must be met for ZDI-CAN-21792 to be exploited?
For ZDI-CAN-21792 to be exploited, the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-21792?
ZDI-CAN-21792 affects Adobe Premiere Pro, specifically versions including Adobe Premiere Pro CS4.