Lucene search

K
cveAdobeCVE-2023-47060
HistoryNov 16, 2023 - 5:15 p.m.

CVE-2023-47060

2023-11-1617:15:08
CWE-824
adobe
web.nvd.nist.gov
42
adobe
premiere pro
cve-2023-47060
access of uninitialized pointer
vulnerability
aslr
exploitation
nvd

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

3.5

Confidence

High

EPSS

0

Percentile

10.9%

Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected configurations

Nvd
Vulners
Node
adobepremiere_proRange23.6
OR
adobepremiere_proMatch24.0
AND
applemacosMatch-
OR
microsoftwindowsMatch-
VendorProductVersionCPE
adobepremiere_pro*cpe:2.3:a:adobe:premiere_pro:*:*:*:*:*:*:*:*
adobepremiere_pro24.0cpe:2.3:a:adobe:premiere_pro:24.0:*:*:*:*:*:*:*
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Premiere Pro",
    "vendor": "Adobe",
    "versions": [
      {
        "lessThanOrEqual": "24.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

3.5

Confidence

High

EPSS

0

Percentile

10.9%