First published: Tue Mar 28 2023(Updated: )
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Dimension | <=3.4.7 | |
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25904 is an Adobe Dimension vulnerability that allows an attacker to execute code in the context of the current user.
CVE-2023-25904 affects Adobe Dimension versions 3.4.7 and earlier by allowing an attacker to perform an out-of-bounds read, leading to a potential code execution.
CVE-2023-25904 has a severity rating of 7.8, which is considered high.
To fix CVE-2023-25904, update Adobe Dimension to version 3.4.8 or later.
You can find more information about CVE-2023-25904 on Adobe's security advisory page: https://helpx.adobe.com/security/products/dimension/apsb23-20.html