CVE-2025-64783
7.8Adobe · DNG SDK
Adobe DNG SDK versions 1.7.0 and earlier are susceptible to an integer overflow flaw that allows local attackers to achieve arbitrary code execution by tricking users into opening malicious files.
Executive summary
Adobe DNG SDK versions 1.7.0 and earlier contain an integer overflow vulnerability that enables arbitrary code execution via a maliciously crafted file.
Vulnerability
The software is affected by an integer overflow or wraparound vulnerability (CWE-190) that occurs during file parsing. Exploitation requires user interaction, specifically forcing a victim to open a specially crafted DNG file, after which an unauthenticated attacker can execute arbitrary code in the context of the current user.
Business impact
The potential for arbitrary code execution poses a significant threat to organizational security, as it could allow an attacker to gain full control over the user's workstation. Given the CVSS score of 7.8, this vulnerability is classified as High severity and represents a substantial risk of data compromise and unauthorized system access.
Remediation
Immediate Action: Update to the patched version of the Adobe DNG SDK as provided in the official vendor security advisory at https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html.
Proactive Monitoring: Monitor systems for unusual file processing errors or unexpected application crashes that might indicate an attempt to trigger an overflow during DNG file ingestion.
Compensating Controls: Implement endpoint protection solutions and restrict the execution of applications that process untrusted media files from unknown or unverified sources.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a high risk due to the potential for arbitrary code execution. Organizations utilizing the Adobe DNG SDK should prioritize applying the vendor-supplied security updates immediately to eliminate this attack vector. Ensure that all downstream applications incorporating this SDK are identified and patched to maintain a secure environment.