First published: Thu Nov 16 2023(Updated: )
Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Photoshop | <=24.7.1 | |
Apple macOS | ||
Microsoft Windows | ||
Adobe Photoshop | <=25.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44333 is a memory corruption vulnerability in Adobe Photoshop versions 24.7.1 and earlier.
An attacker can exploit CVE-2023-44333 by leveraging the out-of-bounds read vulnerability to disclose sensitive memory and bypass mitigations such as ASLR.
Adobe Photoshop versions 24.7.1 and earlier, as well as version 25.0 and earlier, are affected by CVE-2023-44333.
CVE-2023-44333 has a severity rating of 5.5, which is considered medium.
To mitigate CVE-2023-44333 in Adobe Photoshop, it is recommended to update to the latest version available.