Adobe Photoshop Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-21576
7.8HIGH
Summary
Adobe Photoshop versions 23.5.3 and earlier, as well as 24.1 and earlier, are susceptible to an out-of-bounds write vulnerability. This security issue can lead to arbitrary code execution in the context of the current user, necessitating user interaction to be exploited – specifically, the victim must open a specially crafted malicious file. It's critical for users to stay informed about potential threats in order to protect their systems from such vulnerabilities.
Affected Version(s)
Photoshop <= 23.5.3
Photoshop <= 24.1
Photoshop <= unspecified
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved