Impact
Adobe XD suffers from a buffer overflow flaw that lets attackers run arbitrary code in the context of the user who opens a crafted file. This weakness is a classic stack overflow (CWE-120) and can compromise confidentiality, integrity, and availability of the victim’s system. An attacker can embed malicious data in a file and achieve code execution during file import or deserialization.
Affected Systems
The affected product is Adobe XD, with no specific version information provided by the CNA. All versions of Adobe XD that are susceptible to this buffer overflow vulnerability should be considered at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies this issue as high severity. No EPSS score is available, so the exploitation likelihood cannot be quantified, but the absence of a KEV listing indicates that no confirmed widespread exploitation has been reported. The vulnerability requires the victim to open a malicious file, implying that the attack vector is user interaction via a crafted document. Protected systems that allow untrusted file execution are therefore exposed, and once the file is processed the overflow can give the attacker arbitrary code execution rights on the victim’s machine.
OpenCVE Enrichment