Deserialization of Untrusted Data Vulnerability in Adobe Connect
CVE-2025-27203
9.6CRITICAL
What is CVE-2025-27203?
Adobe Connect versions 24.0 and earlier are susceptible to a deserialization of untrusted data issue that may allow attackers to execute arbitrary code. Successful exploitation necessitates user interaction, making it a potential risk for clients who engage with malicious content. Organizations utilizing Adobe Connect are urged to update to the latest version as an essential step in safeguarding their systems.
Affected Version(s)
Adobe Connect 0 <= 24.0
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved