CVE-2021-40742
CVE-2021-40742 is a medium-severity vulnerability in Adobe Audition with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-476.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- CVSS v2: 4.3
- EPSS exploit prediction: 1% (67th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-476
- Affected product: Adobe Audition
- Published:
- Last modified:
Description
Adobe Audition version 14.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Frequently asked questions
- What is CVE-2021-40742?
- Adobe Audition version 14.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- How severe is CVE-2021-40742?
- CVE-2021-40742 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2021-40742 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (67th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-40742?
- CVE-2021-40742 affects Adobe Audition. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-40742?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-40742 published?
- CVE-2021-40742 was published on 2022-03-16 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:adobe:audition:*:*:*:*:*:*:*:*
More vulnerabilities in Adobe Audition
- CVE-2011-0615 — Critical (CVSS 9.3): Multiple buffer overflows in Adobe Audition 3.0.1 and earlier allow remote attackers to execute arbitrary code or cause…
- CVE-2011-0614 — Critical (CVSS 9.3): Buffer overflow in Adobe Audition 3.0.1 and earlier allows remote attackers to cause a denial of service (memory…
- CVE-2026-48368 — High (CVSS 7.8): Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the…
- CVE-2026-48365 — High (CVSS 7.8): Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the…
- CVE-2026-48309 — High (CVSS 7.8): Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the…
- CVE-2026-47968 — High (CVSS 7.8): Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the…
All CVEs affecting Adobe Audition →
Other CWE-476 (NULL Pointer Dereference) vulnerabilities
- CVE-2022-36648 — Critical (CVSS 10.0): The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier,…
- CVE-2020-14500 — Critical (CVSS 10.0): Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
- CVE-2010-2495 — Critical (CVSS 10.0): The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does…
- CVE-2026-67870 — Critical (CVSS 9.8): In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local…
- CVE-2026-53399 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease…
- CVE-2026-53355 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS…
Browse all CWE-476 (NULL Pointer Dereference) vulnerabilities →