CVE-2021-28570

HIGH

Adobe After Effects < 18.1 - Unauthenticated Uncontrolled Search Path Element

Title source: llm
STIX 2.1

Description

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

References (1)

Core 1
Core References
Not Applicable, Vendor Advisory x_refsource_misc
https://helpx.adobe.com/ee/security/products/after_effects/apsb21-33.html

Scores

CVSS v3 8.3
EPSS 0.0178
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
adobe/after_effects < 18.1
Published Jun 28, 2021
Tracked Since Feb 18, 2026