CVE-2025-61817
7.8Adobe · InCopy
Adobe InCopy contains a use after free vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.
Executive summary
Adobe InCopy is affected by a critical use after free vulnerability that could allow an attacker to achieve arbitrary code execution via a malicious file.
Vulnerability
This is a use after free vulnerability (CWE-416) that occurs during file processing. The vulnerability requires user interaction, specifically the opening of a malicious file, to trigger execution in the context of the current user.
Business impact
The ability for an attacker to execute arbitrary code poses a severe risk to organizational security, potentially leading to full system compromise or data theft. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the significant impact on confidentiality, integrity, and availability should a user be successfully lured into opening a weaponized document.
Remediation
Immediate Action: Update Adobe InCopy to the latest patched version as specified in the Adobe security advisory APSB25-107.
Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected child processes spawned by the InCopy executable.
Compensating Controls: Deploy endpoint protection software configured to scan incoming files for malicious patterns and restrict the opening of untrusted files from external sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to end users. Administrators should prioritize the deployment of the vendor-provided security updates across all workstations running InCopy to eliminate the attack surface created by this memory management flaw.