Executive brief
Adobe After Effects is a professional video editing and motion graphics application. A NULL pointer dereference vulnerability in versions 25.6 and earlier allows an attacker to crash the application by sending a specially crafted file, causing service disruption and loss of work for users who open the malicious file.
Technical details
A NULL pointer dereference vulnerability exists in Adobe After Effects 25.6 and earlier. The vulnerability is triggered when the application processes a malicious file, causing a crash that results in a denial-of-service condition. Exploitation requires user interaction—specifically, a victim must open the malicious file. No patch availability information is provided in the advisory, though the CVE publication date suggests vendor notification has occurred.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed