CVE-2023-25905: ZDI-CAN-20031: Adobe Dimension OBJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25905?
CVE-2023-25905 is an out-of-bounds write vulnerability affecting Adobe Dimension versions 3.4.7 and earlier.
What is the severity of CVE-2023-25905?
The severity of CVE-2023-25905 is high, with a severity value of 7.8.
How does CVE-2023-25905 impact Adobe Dimension?
CVE-2023-25905 could result in arbitrary code execution in the context of the current user when a victim opens a malicious file.
Which software versions are affected by CVE-2023-25905?
Adobe Dimension versions 3.4.7 and earlier are affected by CVE-2023-25905.
How can I mitigate the risk of CVE-2023-25905?
To mitigate the risk of CVE-2023-25905, update Adobe Dimension to version 3.4.8 or later, as mentioned in the Adobe security advisory APSB23-20.