Executive brief
Adobe's DNG SDK is a library used by photographers and image processing applications to handle Digital Negative (DNG) image files. An out-of-bounds write vulnerability allows attackers to execute arbitrary code when a victim opens a specially crafted malicious DNG image file, potentially compromising the user's system and data.
Technical details
This vulnerability is an out-of-bounds write in Adobe DNG SDK versions 1.7.1 build 2410 and earlier. The defect occurs when processing malformed or malicious DNG files, allowing an attacker to write data beyond the bounds of an allocated buffer. Exploitation requires user interaction—a victim must be tricked into opening a malicious DNG file. Successful exploitation results in arbitrary code execution in the context of the current user. Adobe has released patches addressing this issue.
Affected products
- Adobe DNG SDK 1.7.1 build 2410 and earlier
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory