cbcvebase.
CVE-2024-39380
published 2024-09-13

CVE-2024-39380: After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected

3 ranges
VendorProductVersion rangeFixed in
adobeafter_effects< 23.6.923.6.9
adobeafter_effects<= 24.5
adobeafter_effects>= 24.0 < 24.624.6