CVE-2024-45108: Photoshop Desktop | Out-of-bounds Write (CWE-787)
Published Sep 13, 2024
·Updated
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
All of the following
Any of the following
Adobe Photoshop<24.7.5
Adobe Photoshop>=25.0<25.12
Any of the following
macOS
Microsoft Windows
Event History
Sep 13, 2024
CVE Published
via MITRE·09:37 AM
Data Sourced
via MITRE·09:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45108?
CVE-2024-45108 has a critical severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-45108?
To fix CVE-2024-45108, update Adobe Photoshop to version 24.7.5 or 25.12 and above.
3
What versions of Photoshop are affected by CVE-2024-45108?
CVE-2024-45108 affects Photoshop Desktop versions 24.7.4, 25.11 and earlier.
4
Can CVE-2024-45108 be exploited remotely?
Exploitation of CVE-2024-45108 requires user interaction, such as opening a malicious file.
5
On which operating systems does CVE-2024-45108 pose a risk?
CVE-2024-45108 poses a risk specifically on versions of Adobe Photoshop running on macOS and Windows.