CVE-2011-2443

Adobe Photoshop Elements <= 8.0 - Buffer Overflow via Crafted .grd or .abr File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-2443. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Adobe Photoshop Elements 8.0 and 7.0 when processing malformed .ABR (brushes) and .GRD (gradients) files, leading to arbitrary code execution or denial of service. The PoC includes crafted files that trigger memory corruption, as evidenced by WinDBG output showing access violations.

Description

Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textdoswindows
https://www.exploit-db.com/exploits/17918

This exploit demonstrates a buffer overflow vulnerability in Adobe Photoshop Elements 8.0 and 7.0 when processing malformed .ABR (brushes) and .GRD (gradients) files, leading to arbitrary code execution or denial of service. The PoC includes crafted files that trigger memory corruption, as evidenced by WinDBG output showing access violations.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Photoshop Elements 8.0 and 7.0
No auth needed
Prerequisites: Victim must open a maliciously crafted .ABR or .GRD file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8410
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17918/

Scores

EPSS 0.1436
EPSS Percentile 96.2%

Details

CWE
CWE-119
Status published
Products (3)
adobe/photoshop_elements 5.0
adobe/photoshop_elements 7.0
adobe/photoshop_elements < 8.0
Published Oct 04, 2011
Tracked Since Feb 18, 2026