CVE-2025-21127

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 427

Summary

CVE-2025-21127 is a vulnerability affecting Adobe Photoshop Desktop versions 25.12 and 26.1 and earlier. This issue involves an Uncontrolled Search Path Element, allowing an attacker to manipulate the search path environment variable and direct it towards a malicious library. This could lead to arbitrary code execution when the application loads. The exploitation of this vulnerability necessitates user interaction as the victim must run the vulnerable application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share