CVE-2025-47107: InCopy | Heap-based Buffer Overflow (CWE-122)
Published Jun 10, 2025
·Updated
InCopy versions 20.2, 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
5 affected components
Adobe InCopy>19.5.3<20.2
All of the following
Any of the following
Adobe InCopy<19.5.4
Adobe InCopy>=20.0<20.3
Any of the following
Apple macOS
Microsoft Windows
Event History
Jun 10, 2025
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47107?
CVE-2025-47107 is classified as a critical severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-47107?
To fix CVE-2025-47107, you should update Adobe InCopy to the latest version beyond 20.2.
3
What does CVE-2025-47107 affect?
CVE-2025-47107 affects Adobe InCopy versions 20.2, 19.5.3, and earlier.
4
What type of vulnerability is CVE-2025-47107?
CVE-2025-47107 is a heap-based buffer overflow vulnerability.
5
What must a user do to trigger CVE-2025-47107?
Exploitation of CVE-2025-47107 requires user interaction, specifically opening a malicious file.