CVE-2021-28570

HIGH

Adobe After Effects < 18.1 - Uncontrolled Search Path

Title source: rule

Description

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

Scores

CVSS v3 8.3
EPSS 0.0077
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

adobe/after_effects < 18.1

Timeline

Published Jun 28, 2021
Tracked Since Feb 18, 2026