CVE-2023-25908: Adobe Photoshop SVG file Use After Free Arbitrary code execution
Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25908?
CVE-2023-25908 is a Use After Free vulnerability in Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) that could allow arbitrary code execution.
How does CVE-2023-25908 work?
CVE-2023-25908 works by exploiting a memory management flaw in Adobe Photoshop, allowing an attacker to execute arbitrary code.
What is the severity of CVE-2023-25908?
CVE-2023-25908 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2023-25908?
To fix CVE-2023-25908, you should update Adobe Photoshop to version 23.5.4 or 24.1.2 (or later) where the vulnerability has been patched.
Where can I find more information about CVE-2023-25908?
You can find more information about CVE-2023-25908 on the Adobe Security Bulletin APSB23-23.