Executive brief
Adobe Audition, a professional audio workstation, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data or the installation of malicious software.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Audition versions 26.0 and 25.6.4 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the logged-in user. The attack vector is local, requiring the victim to manually open a malicious file (User Interaction required). Adobe has released patches in versions 26.3 and 25.6.6 to address this issue.
Affected products
- Adobe Audition <= 26.0, <= 25.6.4
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory