Executive brief
Adobe Audition is a professional audio editing application used by media professionals for mixing, recording, and editing sound. A memory access vulnerability in versions 25.3 and earlier could cause the application to crash or stop responding if an attacker tricks a user into opening a malicious audio file, disrupting work and potentially causing data loss.
Technical details
This vulnerability is a classic buffer overflow issue (CWE-788: Access of Memory Location After End of Buffer) in Adobe Audition's file parsing logic. The vulnerable component fails to properly validate buffer boundaries when processing audio files, allowing out-of-bounds memory access. Exploitation requires user interaction—specifically, opening a crafted malicious audio file within the application. An attacker can trigger a denial-of-service condition causing the application to crash or hang. The vulnerability affects versions 25.3 and earlier; patches are expected to be available through Adobe's security updates.
Affected products
- Adobe Audition 25.3 and earlier
Timeline
- 2026-02-10: disclosed