Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.
-
Adobe After Effects – Used for creating motion graphics, visual effects, and compositing in film, television, and online content.
-
Adobe Substance 3D Viewer – A 3D visualization and editing tool for opening, adjusting, and rendering 3D models.
-
Adobe Audition – Professional audio editing and mixing software for recording, restoring, and producing high-quality sound.
-
Adobe InCopy – A writing and editing tool that integrates with Adobe InDesign for collaborative publishing workflows.
-
Adobe InDesign – Used to design and publish brochures, digital magazines, eBooks, posters, and presentations.
-
Adobe Connect – A web conferencing platform for hosting virtual meetings, webinars, and online training sessions.
-
Adobe Dimension – A 3D design tool for creating photorealistic product mockups and brand visualizations.
-
Adobe Substance 3D Stager – A 3D scene design and rendering tool for assembling and lighting photorealistic compositions.
-
Adobe Illustrator – A vector graphics editor for creating logos, icons, illustrations, and typography.
-
Adobe FrameMaker – A document processor for authoring and publishing large, structured technical documentation.
-
Adobe Experience Manager (AEM) Forms – Enables creation and deployment of digital forms integrated with backend systems.
-
Adobe Experience Manager (AEM) Screens – A digital signage solution for managing interactive experiences across physical displays.
-
Adobe ColdFusion – A rapid web application development platform that supports integration with databases, APIs, and cloud services.
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights
THREAT INTELLIGENCE:
There are currently no reports of these vulnerabilities being exploited in the wild.
SYSTEMS AFFECTED:
-
Adobe After Effects 24.6.6 and earlier versions
-
Adobe After Effects 25.2 and earlier versions
-
Adobe Substance 3D Viewer 0.22 and earlier versions
-
Adobe Audition 24.6.3 and earlier versions
-
Adobe Audition 25.2 and earlier versions
-
Adobe InCopy 20.3 and earlier versions
-
Adobe InCopy 19.5.3 and earlier versions
-
Adobe InDesign ID20.3 and earlier versions
-
Adobe InDesign ID19.5.3 and earlier versions
-
Adobe Connect Windows App 24 and earlier versions
-
Adobe Dimension 4.1.2 and earlier versions
-
Adobe Substance 3D Stager 3.1.2 and earlier versions
-
Illustrator 2025 29.5.1 and earlier versions
-
Illustrator 2024 28.7.6 and earlier versions
-
Adobe FrameMaker 2020 Release Update 8 and earlier versions
-
Adobe FrameMaker 2022 Release Update 6 and earlier versions
-
Adobe Experience Manager (AEM) Forms on JEE 6.5.23.0 and earlier versions
-
Adobe Experience Manager (AEM) Screens on AEM 6.5.22 Screens FP11.4 and earlier versions
-
ColdFusion 2025 Update 2 and earlier versions
-
ColdFusion 2023 Update 14 and earlier versions
-
ColdFusion 2021 Update 20 and earlier versions
RISK:
Government:
-
Large and medium government entities: High
-
Small government entities: Medium
Businesses:
-
Large and medium business entities: High
-
Small business entities: Medium
Home users: Low
TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Details of these vulnerabilities are as follows
Tactic: Execution (TA0002)
Technique: Exploitation for Client Execution (T1203):
Adobe After Effects:
-
NULL Pointer Dereference (CVE-2025-47109)
-
Out-of-bounds Read (CVE-2025-43587)
Substance 3D Viewer:
-
Heap-based Buffer Overflow (CVE-2025-43582)
-
NULL Pointer Dereference (CVE-2025-43583)
-
Out-of-bounds Read (CVE-2025-43584)
Adobe Audition:
-
Access of Memory Location After End of Buffer (CVE-2025-43580)
Adobe InCopy:
-
Integer Underflow Wrap or Wraparound (CVE-2025-47097)
-
Access of Uninitialized Pointer (CVE-2025-47098)
-
Heap-based Buffer Overflow (CVE-2025-47099)
Adobe InDesign:
-
Integer Underflow (Wrap or Wraparound) (CVE-2025-47136)
-
Heap-based Buffer Overflow (CVE-2025-43591, CVE-2025-47103, CVE-2025-47134)
-
Access of Uninitialized Pointer (CVE-2025-43592)
-
Out-of-bounds Write (CVE-2025-43594)
Adobe Connect:
-
Deserialization of Untrusted Data (CVE-2025-27203)
Adobe Dimension:
-
Out-of-bounds Write (CVE-2025-30312)
-
Out-of-bounds Read (CVE-2025-47135)
Substance 3D Stager:
-
Out-of-bounds Read (CVE-2025-27165)
Adobe Illustrator:
-
Out-of-bounds Write (CVE-2025-49526, CVE-2025-49530)
-
Stack-based Buffer Overflow (CVE-2025-49527, CVE-2025-49528)
-
Access of Uninitialized Pointer (CVE-2025-49529)
-
Integer Overflow or Wraparound (CVE-2025-49531)
-
Integer Underflow (Wrap or Wraparound) (CVE-2025-49532)
-
Out-of-bounds Read (CVE-2025-30313, CVE-2025-49525)
-
NULL Pointer Dereference (CVE-2025-49524)
Adobe FrameMaker:
-
Out-of-bounds Write (CVE-2025-47124, CVE-2025-47126, CVE-2025-47127, CVE-2025-47129, CVE-2025-47132, CVE-2025-47133)
-
Access of Uninitialized Pointer (CVE-2025-47121)
-
Heap-based Buffer Overflow (CVE-2025-47122, CVE-2025-47123, CVE-2025-47125, CVE-2025-47131)
-
Integer Underflow (Wrap or Wraparound) (CVE-2025-47128, CVE-2025-47130)
-
Stack-based Buffer Overflow (CVE-2025-47120)
-
NULL Pointer Dereference (CVE-2025-47119)
Adobe Experience Manager Forms:
-
Deserialization of Untrusted Data (CVE-2025-49533)
Adobe Experience Manager Screens:
-
Cross-site Scripting (Reflected XSS) (CVE-2025-49534, CVE-2025-49547)
Adobe ColdFusion:
-
Improper Restriction of XML External Entity Reference ('XXE') (CVE-2025-49535, CVE-2025-49539, CVE-2025-49544)
-
Use of Hard-coded Credentials (CVE-2025-49551)
-
Incorrect Authorization (CVE-2025-49536)
-
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CVE-2025-49537)
-
XML Injection (aka Blind XPath Injection) (CVE-2025-49538)
-
Cross-site Scripting (Stored XSS) (CVE-2025-49540, CVE-2025-49541, CVE-2025-49542, CVE-2025-49543)
-
Server-Side Request Forgery (SSRF) (CVE-2025-49545)
-
Improper Access Control (CVE-2025-49546)
RECOMMENDATIONS:
We recommend the following actions be taken:
-
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
-
Safeguard 7.1 : Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
-

