QID 376460

Date Published: 2022-03-09

QID 376460: Adobe After Effects Arbitrary Code Execution Vulnerability (APSB22-17)

Adobe After Effects is a digital visual effects, motion graphics, and compositing application developed by Adobe Systems and used in the post-production process of film making and television production.

Affected Version(s):
Adobe After Effects Versions for both Windows and MAC OS:
18.4.4 and earlier
22.2 and earlier

QID Detection Logic:(Authenticated)
This QID checks vulnerable version of Adobe After Effects.

Successful exploitation could lead to arbitrary code execution and privilege escalation in the context of the current user.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Adobe has released After Effects version 18.4.5 and 22.2.1 in APSB22-17 to address this vulnerability.

    CVEs related to QID 376460

    Software Advisories
    Advisory ID Software Component Link
    APSB22-17 URL Logo helpx.adobe.com/security/products/after_effects/apsb22-17.html