Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe produces software that is used for creating and publishing a wide variety of content including graphics, photography, illustration, animation, multimedia, motion pictures and print. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights
THREAT INTELLIGENCE:
There are currently no reports of these vulnerabilities being exploited in the wild.
SYSTEMS AFFECTED:
-
Adobe Lightroom 8.2 and earlier versions
-
Adobe Dreamweaver 21.4 and earlier versions
-
Adobe Connect 12.8 and earlier versions
-
Adobe InDesign ID20.2 and earlier versions
-
Adobe InDesign ID19.5.2 and earlier versions
-
Adobe Substance 3D Painter 11.0 and earlier versions
-
Photoshop 2025 26.5 and earlier versions
-
Photoshop 2024 25.12.2 and earlier versions
-
Adobe Animate 2023 23.0.11 and earlier versions
-
Adobe Animate 2024 24.0.8 and earlier versions
-
Illustrator 2025 29.3 and earlier versions
-
Illustrator 2024 28.7.5 and earlier versions
-
Adobe Bridge 14.1.6 and earlier versions
-
Adobe Bridge 15.0.3 and earlier versions
-
Adobe Dimension 4.1.1 and earlier versions
-
Adobe Substance 3D Stager 3.1.1 and earlier versions
-
Adobe Substance 3D Modeler 1.21.0 and earlier versions
-
ColdFusion 2025 and earlier versions
-
ColdFusion 2023 and earlier versions
-
ColdFusion 2021 and earlier versions
RISK:
Government:
-
Large and medium government entities: Medium
-
Small government entities: Medium
Businesses:
-
Large and medium business entities: Medium
-
Small business entities: Medium
Home users: Low
TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Details of these vulnerabilities are as follows
Tactic: Execution (TA0002)
Technique: Exploitation for Client Execution (T1203):
Adobe Lightroom:
-
Out-of-bounds Write (CVE-2025-27197)
Adobe Dreamweaver:
-
Access of Resource Using Incompatible Type ('Type Confusion') (CVE-2025-30310)
Adobe Connect:
-
Cross-site Scripting (Reflected XSS) (CVE-2025-43567, CVE-2025-30314, CVE-2025-30315, CVE-2025-30316)
Adobe InDesign:
-
Out-of-bounds Write (CVE-2025-30318)
-
NULL Pointer Dereference (CVE-2025-30319, CVE-2025-30320)
Substance 3D Painter:
-
Out-of-bounds Write (CVE-2025-30322)
Adobe Photoshop:
-
Integer Underflow (Wrap or Wraparound) (CVE-2025-30324)
-
Integer Overflow or Wraparound (CVE-2025-30325)
-
Access of Uninitialized Pointer (CVE-2025-30326)
Adobe Animate:
-
Out-of-bounds Write (CVE-2025-30328)
-
Integer Underflow (Wrap or Wraparound) (CVE-2025-43555)
-
Integer Overflow or Wraparound (CVE-2025-43556)
-
Access of Uninitialized Pointer (CVE-2025-43557)
-
NULL Pointer Dereference (CVE-2025-30329)
Adobe Illustrator:
-
Heap-based Buffer Overflow (CVE-2025-30330)
Adobe Bridge:
-
Access of Uninitialized Pointer (CVE-2025-43545)
-
Integer Underflow (Wrap or Wraparound) (CVE-2025-43546)
-
Integer Overflow or Wraparound (CVE-2025-43547)
Adobe Dimension:
-
Out-of-bounds Write (CVE-2025-43548, CVE-2025-43572)
Substance 3D Stager:
-
Use After Free (CVE-2025-43549, CVE-2025-43568, CVE-2025-43570, CVE-2025-43571)
-
Out-of-bounds Write (CVE-2025-43569)
-
Out-of-bounds Read (CVE-2025-43551)
Substance 3D Modeler:
-
Uncontrolled Search Path Element (CVE-2025-43553)
-
Out-of-bounds Write (CVE-2025-43554)
Adobe ColdFusion:
-
Improper Input Validation (CVE-2025-43559, CVE-2025-43560)
-
Improper Access Control (CVE-2025-43561, CVE-2025-43563, CVE-2025-43565)
-
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CVE-2025-43562)
-
Incorrect Authorization (CVE-2025-43564)
-
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2025-43566)
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights
RECOMMENDATIONS:
We recommend the following actions be taken:
-
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
-
Safeguard 7.1 : Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
-

