logo

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

ID: 8947723d-b4d6-59bd-acf8-c1978d2a56e4

STIX ID: report--8947723d-b4d6-59bd-acf8-c1978d2a56e4

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-03-11

Date Updated: 2026-04-27

...
...

Multiple vulnerabilities have been disclosed in Adobe products—including Acrobat/Reader, Illustrator, InDesign, and various Substance 3D applications—covering many CVEs and issues (use-after-free, buffer overflows, out-of-bounds read/write, NULL pointer dereference, untrusted search path). The advisory states that the most severe flaws could enable arbitrary code execution as the logged-on user, allowing attackers to install programs, access or modify data, or create accounts; impact varies with user privileges. The report maps the activity to the Execution tactic and the Exploitation for Client Execution technique (T1203).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.