Executive brief
Adobe Audition, a professional audio editing application, contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code with the privileges of the user running the application. An attacker would need to trick a user into opening a specially crafted malicious audio file to trigger the vulnerability. Successful exploitation could result in unauthorized access to user data, installation of malware, or system compromise.
Technical details
The vulnerability is an out-of-bounds write issue in Audition's file parsing logic, occurring in versions 25.3 and earlier. The flaw allows an attacker to write data beyond the bounds of an allocated buffer, typically during the processing of malicious audio files. The attack requires user interaction—a victim must be tricked into opening a malicious file—but no authentication or network access is required. Successful exploitation enables arbitrary code execution in the context of the current user. Adobe has released patches to address this issue.
Affected products
- Adobe Audition 25.3 and earlier
Timeline
- 2026-02-10: disclosed: CVE-2026-21312 published