Executive brief
Adobe Premiere Pro, a professional video editing software used by content creators and production teams, contains an out-of-bounds read vulnerability when parsing maliciously crafted project or media files. An attacker can exploit this by sending a victim a malicious file that, when opened, reads beyond allocated memory and potentially executes arbitrary code with the victim's privileges. This could lead to unauthorized access to sensitive video projects, system compromise, or data theft.
Technical details
The vulnerability is an out-of-bounds read flaw in Premiere Pro's file parsing logic that allows reading past the end of an allocated memory structure when processing a crafted input file. The attack requires user interaction—a victim must explicitly open a malicious file in Premiere Pro. Successful exploitation could allow arbitrary code execution in the context of the current user. The vulnerability affects Premiere Pro versions 25.5 and earlier; a patch is expected to address this issue.
Affected products
- Adobe Premiere Pro 25.5 and earlier
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory