CVE-2015-3112

critical
Published 2015-06-24 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — https://helpx.adobe.com/security/products/photoshop/apsb15-12.html

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — https://helpx.adobe.com/security/products/bridge/apsb15-13.html

OS impact

OSVersionStatusFixed in
macos macosnot-affected

Application impact

VendorProductVersionsFixed
adobebridge{"endIncluding":"6.1"}
adobephotoshop_cc{"endIncluding":"15.2.2"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.