CVE-2021-28570Uncontrolled Search Path Element in Adobe After Effects

Severity
8.6HIGHNVD
CNA8.3
EPSS
0.8%
top 26.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28
Latest updateMay 24

Description

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages2 packages

CVEListV5adobe/after_effectsunspecified18.1+1

🔴Vulnerability Details

2
GHSA
GHSA-x3q8-x67w-r85c: Adobe After Effects version 182022-05-24
CVEList
Adobe After Effects uncontrolled search path element vulnerability could lead to remote code execution2021-06-28
CVE-2021-28570 — Uncontrolled Search Path Element | cvebase