CVE-2025-30307: XMPWorker | Out-of-bounds Read (CWE-125)
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30307?
The severity of CVE-2025-30307 is rated as high due to its potential to disclose sensitive memory information.
How do I fix CVE-2025-30307?
To fix CVE-2025-30307, upgrade to a version of Adobe XMP Toolkit later than 2023.12.
What type of vulnerability is CVE-2025-30307?
CVE-2025-30307 is an out-of-bounds read vulnerability that allows attackers to exploit sensitive memory issues.
What product is affected by CVE-2025-30307?
CVE-2025-30307 affects the Adobe XMP Toolkit versions up to 2023.12.
How can attackers exploit CVE-2025-30307?
Attackers can exploit CVE-2025-30307 by leveraging user interaction to bypass security mitigations such as ASLR.