CVE-2024-41867

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

16 Sep 2024, 13:15

Type Values Removed Values Added
Summary (en) After Effects versions 23.6.6, 24.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could lead to arbitrary file system write operations. An attacker could leverage this vulnerability to modify or corrupt files, potentially leading to a compromise of system integrity. Exploitation of this issue requires user interaction in that a victim must open a malicious file. (en) After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE CWE-121 CWE-125

13 Sep 2024, 17:27

Type Values Removed Values Added
First Time Apple macos
Apple
Microsoft
Microsoft windows
CWE CWE-119 CWE-787
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

13 Sep 2024, 16:48

Type Values Removed Values Added
CPE cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:*
First Time Adobe after Effects
Adobe
CWE CWE-119
References () https://helpx.adobe.com/security/products/after_effects/apsb24-55.html - () https://helpx.adobe.com/security/products/after_effects/apsb24-55.html - Vendor Advisory

13 Sep 2024, 14:06

Type Values Removed Values Added
Summary
  • (es) Las versiones 23.6.6, 24.5 y anteriores de After Effects se ven afectadas por una vulnerabilidad de desbordamiento de búfer basada en pila que podría provocar operaciones de escritura arbitrarias en el sistema de archivos. Un atacante podría aprovechar esta vulnerabilidad para modificar o dañar archivos, lo que podría poner en riesgo la integridad del sistema. Para aprovechar este problema, es necesario que el usuario abra un archivo malicioso.

13 Sep 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-13 09:15

Updated : 2024-09-16 13:15


NVD link : CVE-2024-41867

Mitre link : CVE-2024-41867

CVE.ORG link : CVE-2024-41867


JSON object : View

Products Affected

adobe

  • after_effects

apple

  • macos

microsoft

  • windows
CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write