Executive brief
Adobe DNG SDK is a software tool used by developers to handle Digital Negative (DNG) image files in various applications. A security flaw in this tool could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted, malicious image file. This could lead to unauthorized access to sensitive data or the installation of harmful software.
Technical details
A heap-based buffer overflow (CWE-122) exists in Adobe DNG SDK versions 1.7.1 2536 and earlier. The vulnerability is triggered when the SDK processes a malformed DNG file, leading to memory corruption. An attacker can exploit this by providing a specially crafted file to a user; if the user opens the file with an application utilizing the vulnerable SDK, the attacker could achieve arbitrary code execution with the privileges of the current user. The attack vector is local and requires user interaction (UI:R). Adobe has addressed this issue in newer versions of the SDK.
Affected products
- Adobe DNG SDK 1.7.1 2536 and earlier
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory