CVE-2025-64783: DNG SDK | Integer Overflow or Wraparound (CWE-190)
Published Dec 9, 2025
·Updated
DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
DNG DNG SDK<=1.7.0
All of the following
Adobe DNG Software Development Kit<=1.7.0
Any of the following
Apple macOS
Microsoft Windows
Event History
Dec 9, 2025
CVE Published
via MITRE·05:41 PM
Data Sourced
via MITRE·05:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64783?
CVE-2025-64783 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2025-64783?
To mitigate CVE-2025-64783, users should upgrade to a version of DNG SDK that is later than 1.7.0.
3
What type of vulnerability is CVE-2025-64783?
CVE-2025-64783 is an Integer Overflow or Wraparound vulnerability.
4
What software is affected by CVE-2025-64783?
CVE-2025-64783 affects DNG SDK versions 1.7.0 and earlier.
5
What is required for an attacker to exploit CVE-2025-64783?
Exploitation of CVE-2025-64783 requires user interaction, specifically opening a malicious file.