
Cloud Vulnerability DB
A community-led vulnerabilities database
Adobe After Effects versions 17.1 and earlier were found to contain a heap overflow vulnerability identified as CVE-2020-9637. The vulnerability was discovered and disclosed in March 2020, with Adobe releasing patches in June 2020. This security flaw specifically affects the AfterFXLib module when processing AEPX files (Fortinet Research, Adobe Advisory).
The vulnerability is classified as a heap overflow vulnerability that occurs during the decoding of AEPX files in Adobe After Effects. The flaw is specifically caused by a malformed AEPX file that triggers a heap overflow due to improper bounds checking in the AfterFXLib module. The vulnerability has received a CVSS v3.1 base score of 7.8 (High), with a vector string of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD, Fortinet Research).
Successful exploitation of this vulnerability could lead to arbitrary code execution within the context of the application. An attacker could potentially execute malicious code with the same privileges as the affected application, potentially compromising the system's security (NVD, Fortinet Research).
The vulnerability can be exploited through a specially crafted AEPX file. At the time of disclosure, there were no known exploits of this vulnerability in the wild (Threatpost).
Adobe addressed this vulnerability by releasing version 17.1.1 of After Effects. Users of affected versions are strongly encouraged to update to the latest version to mitigate this security risk. Additionally, Fortinet released an IPS signature named Adobe.After.Effects.CVE-2020-9637.Memory.Corruption to protect their customers before the patch became available (Fortinet Research, Adobe Advisory).
The vulnerability was discovered by Honggang Ren of Fortinet's FortiGuard Labs, highlighting the collaborative effort between security researchers and software vendors in identifying and addressing security vulnerabilities. The fix was part of an out-of-band update that addressed multiple critical vulnerabilities in Adobe products (Threatpost).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."