DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
References
| Link | Resource |
|---|---|
| https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
10 Dec 2025, 16:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:a:adobe:dng_software_development_kit:*:*:*:*:*:*:*:* |
|
| References | () https://helpx.adobe.com/security/products/dng-sdk/apsb25-118.html - Vendor Advisory | |
| First Time |
Adobe
Microsoft Microsoft windows Apple macos Apple Adobe dng Software Development Kit |
09 Dec 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 18:16
Updated : 2025-12-10 16:03
NVD link : CVE-2025-64784
Mitre link : CVE-2025-64784
CVE.ORG link : CVE-2025-64784
JSON object : View
Products Affected
microsoft
- windows
adobe
- dng_software_development_kit
apple
- macos
CWE
CWE-122
Heap-based Buffer Overflow
