Heap-based Buffer Overflow in InCopy by Adobe
CVE-2025-47107

7.8HIGH

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
10 June 2025

What is CVE-2025-47107?

InCopy versions 20.2, 19.5.3, and earlier are subject to a heap-based buffer overflow vulnerability that can allow arbitrary code execution. This security issue requires user interaction, specifically that a user must open a compromised file crafted with malicious intent. When exploited, this vulnerability can compromise the system's integrity by executing unauthorized code in the context of the user currently logged in.

Affected Version(s)

InCopy 0 <= 19.5.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.