CVE-2025-61817

7.8

Adobe · InCopy

Adobe InCopy contains a use after free vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.

Executive summary

Adobe InCopy is affected by a critical use after free vulnerability that could allow an attacker to achieve arbitrary code execution via a malicious file.

Vulnerability

This is a use after free vulnerability (CWE-416) that occurs during file processing. The vulnerability requires user interaction, specifically the opening of a malicious file, to trigger execution in the context of the current user.

Business impact

The ability for an attacker to execute arbitrary code poses a severe risk to organizational security, potentially leading to full system compromise or data theft. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the significant impact on confidentiality, integrity, and availability should a user be successfully lured into opening a weaponized document.

Remediation

Immediate Action: Update Adobe InCopy to the latest patched version as specified in the Adobe security advisory APSB25-107.

Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected child processes spawned by the InCopy executable.

Compensating Controls: Deploy endpoint protection software configured to scan incoming files for malicious patterns and restrict the opening of untrusted files from external sources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant risk to end users. Administrators should prioritize the deployment of the vendor-provided security updates across all workstations running InCopy to eliminate the attack surface created by this memory management flaw.

More Adobe CVEs

Sources