CVE-2021-40735 is a memory corruption vulnerability in Adobe Audition versions 14.4 and earlier, affecting both Windows and macOS platforms. This high-severity flaw (CVSS 7.8) requires user interaction and local access to execute arbitrary code with the privileges of the current user, potentially leading to full compromise of the affected system. While no public exploits or Metasploit modules are available, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community. It is not currently listed on CISA's KEV catalog, suggesting no widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.4CPE matchmatch criteria | cpe:2.3:a:adobe:audition:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.