QID 379023

Date Published: 2023-11-20

QID 379023: Adobe Media Encoder Arbitrary Code Execution Out-of-bounds Read and Write Vulnerability (APSB23-63)

Adobe has released an update for Adobe Media Encoder. This update resolves a critical file parsing vulnerability.

Affected Versions:
Adobe Media Encoder 23.6 and earlier versions
Adobe Media Encoder 24.0.2 and earlier versions

QID Detection Logic :
This QID checks for vulnerable version of Adobe Media Encoder

Successful exploitation of this vulnerability could lead to arbitrary code execution and memory leak.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Adobe has released fix to address this issue. Customers are advised to refer to APSB23-63 for updates pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    APSB23-63 URL Logo helpx.adobe.com/security/products/media-encoder/apsb23-63.html