Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vulnerable application.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Jan 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vulnerable application. | |
Title | Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2025-01-14T18:53:10.445Z
Updated: 2025-01-14T21:09:47.598Z
Reserved: 2024-12-04T17:19:21.472Z
Link: CVE-2025-21127
Vulnrichment
Updated: 2025-01-14T21:09:29.139Z
NVD
Status : Received
Published: 2025-01-14T19:15:33.230
Modified: 2025-01-14T19:15:33.230
Link: CVE-2025-21127
Redhat
No data.