ZDI-CAN-24051: ZDI-24-1200: Adobe Media Encoder AVI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Media Encoder. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-39377.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24051?
The severity of ZDI-CAN-24051 is significant due to its ability to allow remote code execution on affected installations of Adobe Media Encoder.
How do I fix ZDI-CAN-24051?
To fix ZDI-CAN-24051, update Adobe Media Encoder to the latest version provided by Adobe.
What types of attacks can exploit ZDI-CAN-24051?
ZDI-CAN-24051 can be exploited through attacks that require user interaction, such as visiting a malicious webpage or opening a malicious file.
Which versions of software are affected by ZDI-CAN-24051?
ZDI-CAN-24051 affects Adobe Media Encoder 2022 installations.
Is user interaction required to exploit ZDI-CAN-24051?
Yes, user interaction is required to exploit ZDI-CAN-24051.