CVE-2025-61818
7.8Adobe · InCopy
Adobe InCopy contains a use after free vulnerability that may allow a local attacker to achieve arbitrary code execution upon opening a malicious file.
Executive summary
Adobe InCopy versions 19.5.5 and earlier are vulnerable to a use after free flaw that could lead to arbitrary code execution, requiring user interaction to trigger.
Vulnerability
This is a use after free vulnerability (CWE-416) that occurs when the software improperly manages memory, allowing an attacker to execute arbitrary code in the context of the current user. Successful exploitation requires the victim to open a specially crafted malicious file.
Business impact
The potential for arbitrary code execution poses a significant risk to organizational security, as it could allow an attacker to gain control over the user session, exfiltrate sensitive data, or install persistent malware. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the potential for total impact on confidentiality, integrity, and availability within the local user context.
Remediation
Immediate Action: Update Adobe InCopy to the latest version as specified in the official vendor advisory (APSB25-107).
Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected file access patterns that may indicate attempts to trigger memory corruption.
Compensating Controls: Implement endpoint protection solutions that can detect and block the execution of malicious files and restrict the ability of applications to launch unauthorized processes.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the severity of potential code execution, it is imperative that all affected Adobe InCopy installations are patched immediately. Administrators should prioritize deploying the vendor-supplied updates to mitigate the risk of exploitation through malicious file attachments or shared documents.