- Description
- Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vulnerable application.
- Source
- psirt@adobe.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@adobe.com
- CWE-427
- Hype score
- Not currently trending
🔴 Photoshop, Uncontrolled Search Path Element Vulnerability #CVE-2025-21127 (High) https://t.co/Yy7GxyZXrF
@dailycve
11 Feb 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe Photoshop node_modules Uncontrolled Search Path Element Local Privilege Escalation Vulnerability (CVE-2025-21127) #Adobe #AdobePhotoshop #CVE202521127 #CyberSecurity #LocalPrivilegeEscalation https://t.co/Papxi3reQA
@SystemTek_UK
21 Jan 2025
14 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Adobe: Critical Code Execution Flaws in Photoshop - (CVE-2025-21127, CVE-2025-21122) - https://t.co/A5TPnguyyo
@SecurityWeek
14 Jan 2025
109 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16B774EA-142E-47DF-A0C6-8B5E13C28481",
"versionEndExcluding": "25.12.1",
"versionStartIncluding": "25.0"
},
{
"criteria": "cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B70D193F-0DD5-4D02-9CAA-5F5DDC42BCF4",
"versionEndExcluding": "26.2",
"versionStartIncluding": "26.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]