CVE-2025-47097: InCopy | Integer Underflow (Wrap or Wraparound) (CWE-191)
InCopy versions 20.3, 19.5.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47097?
CVE-2025-47097 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2025-47097?
To mitigate CVE-2025-47097, upgrade Adobe InCopy to version 20.4 or later as soon as possible.
What are the affected versions for CVE-2025-47097?
CVE-2025-47097 affects Adobe InCopy versions 19.5.3 and earlier, up to version 20.3.
What type of vulnerability is CVE-2025-47097?
CVE-2025-47097 is an Integer Underflow vulnerability that could lead to arbitrary code execution.
Does CVE-2025-47097 require user interaction for exploitation?
Yes, exploitation of CVE-2025-47097 requires the user to open a malicious file.