Cyber Posture

CVE-2025-21127

High

Published: 14 January 2025

Published
14 January 2025
Modified
11 February 2025
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0014 33.9th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vulnerable application.

Security Summary

CVE-2025-21127 is an Uncontrolled Search Path Element vulnerability (CWE-427) affecting Adobe Photoshop Desktop versions 25.12, 26.1, and earlier. The flaw allows an attacker to manipulate the search path environment variable to direct the application toward a malicious library, leading to arbitrary code execution when Photoshop loads the library. Published on January 14, 2025, the vulnerability carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Exploitation requires local access to the victim's system with no privileges needed, though user interaction is mandatory as the victim must launch the vulnerable Photoshop application. A malicious actor could leverage this by altering environment variables—such as PATH or LD_LIBRARY_PATH—to prioritize a controlled DLL or shared object, enabling full arbitrary code execution with high impact on confidentiality, integrity, and availability upon application startup.

Adobe's security bulletin APSB25-02, available at https://helpx.adobe.com/security/products/photoshop/apsb25-02.html, addresses this issue and provides guidance on mitigation, including recommendations to apply the latest security updates for affected Photoshop versions.

Details

CWE(s)
CWE-427

Affected Products

adobe
photoshop
25.0 — 25.12.1 · 26.0 — 26.2

References