CVE-2025-54242

7.8

Adobe · Premiere Pro

Adobe Premiere Pro contains a Use After Free vulnerability that may allow a local attacker to achieve arbitrary code execution via a malicious file.

Executive summary

Adobe Premiere Pro is affected by a critical Use After Free vulnerability that could lead to arbitrary code execution if a user opens a specially crafted file.

Vulnerability

This vulnerability is a Use After Free flaw, identified as CWE-416, which occurs during file processing. An attacker can trigger this condition by convincing a user to open a malicious file, leading to code execution in the context of the current user.

Business impact

The ability for an attacker to execute arbitrary code on a victim's machine poses a significant risk to organizational data integrity and system security. With a CVSS score of 7.8, this high-severity vulnerability could allow unauthorized access to sensitive projects, intellectual property, or local network resources. Successful exploitation results in full control over the application process, potentially leading to complete system compromise for the affected user.

Remediation

Immediate Action: Update Adobe Premiere Pro to the latest patched version as specified in the Adobe security bulletin APSB25-87.

Proactive Monitoring: Monitor endpoint processes for unusual child process creation or unexpected memory usage patterns associated with Adobe Premiere Pro.

Compensating Controls: Implement strict file-handling policies and utilize endpoint security solutions to scan files from untrusted sources before they are opened by Adobe applications.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability presents a serious risk to any environment utilizing Adobe Premiere Pro. Organizations should prioritize updating all instances to the vendor-recommended version immediately to eliminate the possibility of arbitrary code execution. Given the nature of the flaw, user awareness regarding opening files from untrusted sources is also strongly advised until all systems are fully patched.

More Adobe CVEs

Sources