AI analysis
Adobe Photoshop Desktop contains an integer overflow or wraparound condition (CWE-190) that, when the application processes a specially crafted file, can lead to arbitrary code execution. Exploitation uses a local attack vector and requires user interaction: an attacker must trick a victim into opening a malicious file, which triggers the flawed integer arithmetic. A successful attacker gains code execution in the context of the current user, meaning the privileges of the logged-in account rather than system-level control. All users running the affected desktop releases of Photoshop are potentially exposed; this data set does not include specific version ranges, which are enumerated in Adobe's security advisory. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.
What to do: Update Photoshop Desktop to the fixed release listed in Adobe's security advisory (specific version numbers are not included in this data) using the Creative Cloud updater. Until patched, instruct users not to open image or design files from untrusted sources, since exploitation requires a victim to open a malicious file. Given no known PoC or in-the-wild exploitation and a low ~0.2% EPSS score, patching can follow the normal high-priority cycle rather than emergency response.
Affected
| Adobe Photoshop (Desktop) | — |
Estimated exposure
masstens of millions of desktop users (Photoshop is the flagship app of Adobe's ~30M-subscriber Creative Cloud) — Adobe does not publish per-application install counts, but Photoshop is the most widely deployed application in a Creative Cloud ecosystem reported to exceed 30 million subscribers, so the installed desktop base is plausibly in the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.