Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Adobe Photoshop Vulnerability Let Attackers Execute Arbitrary Code

Posted on May 14, 2025May 15, 2025 By CWS

Adobe has launched vital safety updates for Photoshop on each Home windows and macOS platforms after discovering a number of extreme vulnerabilities that would enable attackers to execute arbitrary code on victims’ techniques. 

The safety bulletin addresses three vital flaws affecting Photoshop 2025 (model 26.5 and earlier) and Photoshop 2024 (model 25.12.2 and earlier).

A number of Important Flaws Found in Adobe Photoshop

Probably the most regarding side of those flaws is their potential to permit menace actors to execute arbitrary code on affected techniques, probably main to finish system compromise.

The primary vulnerability (CVE-2025-30324) is assessed as an Integer Underflow (Wrap or Wraparound) weak spot, following the Frequent Weak point Enumeration normal CWE-191. 

This kind of flaw happens when mathematical operations trigger an integer worth to wrap round its minimal or most, resulting in surprising habits that attackers can exploit.

The second vulnerability (CVE-2025-30325) entails an Integer Overflow or Wraparound subject (CWE-190), the place mathematical operations trigger an identical boundary violation however in the wrong way. 

Each integer-related vulnerabilities obtained a Important severity ranking with a CVSS base rating of seven.8.

The third vulnerability (CVE-2025-30326) stems from Entry of Uninitialized Pointer (CWE-824), the place the software program makes an attempt to entry reminiscence through a pointer earlier than it has been initialized. 

This flaw additionally obtained a Important severity ranking with the identical CVSS vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

In keeping with Adobe’s safety bulletin, profitable exploitation of any of those vulnerabilities may result in arbitrary code execution within the context of the present consumer. 

If the consumer has administrative privileges, an attacker may probably take full management of the affected system, set up packages, view, change, or delete information, or create new accounts with full consumer rights.

“Thankfully, Adobe is just not conscious of any exploits within the wild for any of the problems addressed in these updates,” the corporate acknowledged in its safety bulletin. 

Nevertheless, safety consultants suggest speedy patching as a result of vital nature of those flaws.

CVEsAffected ProductsImpactExploit PrerequisitesCVSS 3.1 ScoreCVE-2025-30324CVE-2025-30325 CVE-2025-30326Photoshop 2025 (≤26.5), Photoshop 2024 (≤25.12.2)Arbitrary Code ExecutionLocal entry, consumer interplay, no privileges7.8 (Important)

Safety Updates Out there 

Adobe has launched up to date variations of the affected software program to handle these vulnerabilities. Customers of Photoshop 2025 ought to replace to model 26.6, whereas Photoshop 2024 customers ought to replace to model 25.12.3. 

The corporate has assigned a Precedence 3 ranking to those updates, indicating the vulnerabilities have an effect on merchandise which have traditionally not been focused by attackers.

Customers can replace their software program through the Artistic Cloud desktop utility’s replace mechanism. For managed environments, IT directors can deploy the updates by way of the Admin Console.

Adobe acknowledged safety researcher “yjdfy” for responsibly disclosing all three vulnerabilities and collaborating with the corporate to guard prospects. 

The corporate maintains a public bug bounty program with HackerOne for exterior safety researchers interested by contributing to Adobe’s safety efforts.

All Photoshop customers are strongly urged to replace to the newest versions-Photoshop 2025 (26.6) and Photoshop 2024 (25.12.3)-as quickly as doable to mitigate any threat. Staying vigilant and preserving software program present stays the perfect protection in opposition to evolving cyber threats.

Leveraging Defensive AI for Endpoint Safety to cease threats with 99.5% accuracy – Be part of Free Seminar

Cyber Security News Tags:Adobe, Arbitrary, Attackers, Code, Execute, Photoshop, Vulnerability

Post navigation

Previous Post: CTM360 Identifies Surge in Phishing Attacks Targeting Meta Business Users
Next Post: Samsung MagicINFO 9 Server Vulnerability Let Attackers Write Arbitrary File

Related Posts

DPRK’s Largest Cryptocurrency Heist via a Compromised macOS Developer and AWS Pivots Cyber Security News
Earth Ammit Hackers Attacking Using New Tools to Attack Drones Used in Military Sectors Cyber Security News
Samsung MagicINFO 9 Server Vulnerability Let Attackers Write Arbitrary File Cyber Security News
“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram Cyber Security News
Cybersecurity Industry Gains $1.7 Billion to Develop Cutting-Edge Protection Technologies Cyber Security News
AI Security Frameworks – Ensuring Trust in Machine Learning Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Printer Company Procolored Served Infected Software for Months
  • RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer
  • Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access
  • UK Legal Aid Agency Finds Data Breach Following Cyberattack
  • 480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2025

Recent Posts

  • Printer Company Procolored Served Infected Software for Months
  • RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer
  • Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access
  • UK Legal Aid Agency Finds Data Breach Following Cyberattack
  • 480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News