CVE-2024-49537: Adobe After Effects

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected products

  • Adobe After Effects: before 24.6.3 (fixed in 24.6.3); from 25.0, before 25.1 (fixed in 25.1)

Published 2024-12-10. Last modified 2026-06-17.