ZDI-CAN-24026: ZDI-24-1332: Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Dimension. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-45146.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24026?
ZDI-CAN-24026 has been assigned a CVSS rating indicating a high severity due to the potential for remote code execution.
How do I fix ZDI-CAN-24026?
To fix ZDI-CAN-24026, you should apply the latest security updates provided by Adobe for Adobe Dimension.
What types of attacks can be executed due to ZDI-CAN-24026?
ZDI-CAN-24026 allows for remote code execution attacks which could lead to complete system compromise.
Is user interaction required to exploit ZDI-CAN-24026?
Yes, user interaction is required for ZDI-CAN-24026 as the target must open a malicious file or visit a malicious page.
What versions of Adobe Dimension are affected by ZDI-CAN-24026?
ZDI-CAN-24026 affects all installations of Adobe Dimension that have not been updated to correct the vulnerability.