CVE-2025-54256
8.6Adobe · Dreamweaver Desktop
Adobe Dreamweaver Desktop versions 21.5 and earlier are vulnerable to Cross-Site Request Forgery (CSRF), which can lead to arbitrary code execution in the context of the current user.
Executive summary
Adobe Dreamweaver Desktop versions 21.5 and earlier contain a critical CSRF vulnerability that allows for arbitrary code execution upon user interaction.
Vulnerability
This is a Cross-Site Request Forgery (CWE-352) vulnerability that enables an attacker to execute arbitrary code. The attack requires user interaction, specifically that a victim clicks on a malicious link, and the impact occurs within the scope of the current user session.
Business impact
The potential for arbitrary code execution poses a significant risk to organizational assets. If exploited, an attacker could gain control over the user session, potentially leading to unauthorized data access, system modification, or further compromise of the local environment. With a CVSS score of 8.6, this vulnerability is classified as High severity and requires immediate attention to prevent potential system-wide impacts.
Remediation
Immediate Action: Review the official Adobe security bulletin at https://helpx.adobe.com/security/products/dreamweaver/apsb25-91.html and apply any available security updates or patches provided by the vendor.
Proactive Monitoring: Monitor system logs for unusual outbound requests or unexpected application behavior following the opening of external links or documents.
Compensating Controls: Educate users on the risks of clicking untrusted links and ensure that organizational security policies restrict the execution of unauthorized scripts within the desktop environment.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the High severity rating and the potential for arbitrary code execution, it is imperative that all instances of Adobe Dreamweaver Desktop are updated as soon as a patch is made available by Adobe. Security teams should prioritize this update to mitigate the risk of remote compromise through malicious link interaction.