cbcvebase.
CVE-2007-2365
published 2007-04-30

CVE-2007-2365: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute…

PriorityP352critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
51.05%
98.8th percentile
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

Affected

4 ranges
VendorProductVersion rangeFixed in
adobegolive
adobeillustrator
adobephotoshop
adobephotoshop_elements

Detection & IOCsextracted from sources · hover to see the quote

filename.png
bytes
\x89\x50\x4e\x47\x0d\x0a\x1a\x0a\x00\x00\x00\x0d\x49\x48\x44\x52
  • Exploit payload uses PexFnstenvSub encoder (Metasploit); network or endpoint detection should look for this encoder's characteristic byte patterns (\x29\xc9\x83\xe9 or \x31\xc9\x83\xe9) embedded inside PNG files.
  • Bind-shell payload listens on TCP port 4444 after successful exploitation; monitor for unexpected outbound/inbound connections on port 4444 from Photoshop or related processes.
  • The exploit targets Windows XP SP2; prioritize detection on legacy Windows XP endpoints running the affected Adobe/Corel applications.
  • The malicious PNG contains a valid PNG header (\x89PNG\r\n\x1a\n) followed by an IHDR chunk and then a large IDAT block embedding shellcode; inspect PNG files for shellcode patterns within compressed IDAT data.
  • ·The exploit was tested specifically against Windows XP SP2 French edition; exploit reliability on other OS versions or service packs is not confirmed by the source.
  • ·The vulnerability also affects Adobe Illustrator CS3 and GoLive 9 per the NVD advisory, but the proof-of-concept exploit code only targets Photoshop CS2/CS3, Photoshop Elements 5.0, and Corel Paint Shop Pro 11.20.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.