CVE-2021-28607 describes a heap corruption vulnerability in Adobe After Effects versions 18.2 and earlier, affecting both Windows and macOS installations. This flaw allows an unauthenticated attacker to achieve arbitrary code execution if a user opens a specially crafted malicious file. Rated 7.8 HIGH on CVSS, it requires user interaction and local access for exploitation, but could lead to high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available, it is not listed in CISA's KEV catalog, and has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.2CPE match | cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.