First published: Wed Oct 11 2023(Updated: )
Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Photoshop 2022 | <=23.5.5 | |
Adobe Photoshop 2023 | <24.7.1 | |
Adobe Photoshop 2024 | <25.0 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26370 is an Access of Uninitialized Pointer vulnerability in Adobe Photoshop versions 23.5.5 and earlier, as well as version 24.7 and earlier.
CVE-2023-26370 has a severity score of 7.8, which is considered high.
Exploiting the Access of Uninitialized Pointer vulnerability in Adobe Photoshop requires user interaction, where a victim must open a malicious file.
Adobe Photoshop versions 23.5.5 and earlier, as well as version 24.7 and earlier, are affected by CVE-2023-26370.
You can find more information about CVE-2023-26370 on the Adobe Security Bulletin APSB23-51.