CVE-2025-61819

7.8

Adobe · Photoshop Desktop

Adobe Photoshop Desktop versions 26.8.1 and earlier contain a heap-based buffer overflow vulnerability that may allow an attacker to achieve arbitrary code execution via a malicious file.

Executive summary

A critical heap-based buffer overflow vulnerability in Adobe Photoshop Desktop allows for arbitrary code execution when a user opens a specially crafted malicious file.

Vulnerability

This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the software processes a malformed file. Successful exploitation requires user interaction, specifically the victim opening a malicious file, but does not require prior authentication.

Business impact

The ability for an attacker to execute arbitrary code in the context of the current user presents a significant risk to organizational security. This could lead to full system compromise, data theft, or the installation of persistent malware within the workstation environment. With a CVSS score of 7.8, the vulnerability is classified as High severity, reflecting the potential for total loss of confidentiality, integrity, and availability for the affected host.

Remediation

Immediate Action: Update Adobe Photoshop Desktop to the latest version provided in the Adobe security bulletin APSB25-108.

Proactive Monitoring: Monitor workstation endpoint logs for abnormal application crashes or unexpected child processes spawning from the Photoshop executable.

Compensating Controls: Implement endpoint protection solutions that scan incoming files for malicious signatures and utilize application control policies to restrict the execution of untrusted software.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, security teams should prioritize the update of all Adobe Photoshop installations across the enterprise. Users should be reminded to exercise caution when opening files from untrusted or unknown sources, as this remains the primary vector for exploitation until the software is patched.

More Adobe CVEs

Sources