CVE-2026-47971
Analyzed Analyzed - Analysis Complete

Stack-based Buffer Overflow in Media Encoder

Vulnerability report for CVE-2026-47971, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-17

Assigner: Adobe Systems Incorporated

Description

Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-17
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
adobe media_encoder to 25.6.5 (inc)
adobe media_encoder From 26.0 (inc) to 26.2.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Media Encoder has a stack-based buffer overflow flaw that may allow attackers to run arbitrary code on a victim's system. This requires the victim to open a specially crafted malicious file.

Detection Guidance

Detection requires monitoring for crashes or unusual behavior when opening media files in Adobe Media Encoder. Check for application logs for segmentation faults or buffer overflow errors. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could let attackers take control of your computer, install malware, or steal sensitive data. It requires user interaction, meaning you must open a malicious file for it to work.

Compliance Impact

The vulnerability allows arbitrary code execution via user interaction with a malicious file, which could lead to unauthorized data access or modification. This may violate GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information if exploited.

Mitigation Strategies

Apply the latest security patches from Adobe immediately. Avoid opening untrusted media files. Disable automatic file opening in Adobe Media Encoder if possible. Monitor Adobe's security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47971. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart