CVE-2022-38432: Adobe Photoshop SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Sep 16, 2022
·Updated
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Photoshop>=22.0<=22.5.8
Adobe Photoshop>=23.0<=23.4.2
macOS
Microsoft Windows
Event History
Sep 16, 2022
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Photoshop vulnerability?
The vulnerability ID for this Adobe Photoshop vulnerability is CVE-2022-38432.
2
What is the severity of CVE-2022-38432?
CVE-2022-38432 has a severity rating of 7.8 (high).
3
Which versions of Adobe Photoshop are affected by CVE-2022-38432?
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by CVE-2022-38432.
4
How does CVE-2022-38432 potentially impact users?
CVE-2022-38432 could result in arbitrary code execution in the context of the current user if exploited.
5
How can CVE-2022-38432 be mitigated?
To mitigate CVE-2022-38432, users should update to the latest version of Adobe Photoshop.