Executive brief
Adobe Media Encoder, a professional video and audio processing application, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the execution of malicious software in the context of the logged-in user.
Technical details
A stack-based buffer overflow (CWE-121) exists in Adobe Media Encoder versions 26.2.2 and 25.6.5 and earlier. The vulnerability is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. This is a local attack vector requiring user interaction (UI:R). The issue is resolved in versions 26.3 and 25.6.6.
Affected products
- Adobe Media Encoder <= 26.2.2, <= 25.6.5
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-72
- 2026-07-14: disclosed