Executive brief
Adobe Premiere Pro, a professional video editing application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious project or media file. If successful, the attacker could execute unauthorized commands or install software with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Premiere Pro. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution in the context of the current user. The attack vector is local, requiring the victim to manually open a malicious file (User Interaction: Required). Adobe has addressed this in updated versions of the software.
Affected products
- Adobe Premiere Pro <= 25.6.4, 26.0.0 to 26.0.2
Timeline
- 2026-05-12: advisory: Initial advisory published by Adobe
- 2026-05-12: disclosed