Heap-based Buffer Overflow in DNG SDK by Adobe
CVE-2025-64784

7.1HIGH

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-64784?

The DNG SDK from Adobe is susceptible to a Heap-based Buffer Overflow vulnerability, present in version 1.7.0 and prior. This vulnerability enables potential attackers to exploit the affected software by leveraging malicious files, leading to unauthorized memory exposure or application crashes. User interaction is essential for exploitation, as victims must open the harmful file for the attack to be effective. It is critical for users to stay informed and apply necessary updates to mitigate this risk.

Affected Version(s)

DNG SDK 0 <= 1.7.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64784 : Heap-based Buffer Overflow in DNG SDK by Adobe