External risk intelligence

Adobe XD Path Traversal Vulnerability Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2019-7106

Adobe XD is a desktop-based application used for UI/UX design. It is a client-side software product installed locally on user workstations, not a network-accessible service, server, or gateway. Consequently, it lacks a public-facing attack surface.

Path Traversal

Adobe Xd

before 17.0.12

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Adobe XD software that could allow attackers to execute arbitrary code by exploiting a path traversal flaw. The primary concern is to confirm if this specific software is in use and assess potential exposure.

  • Flaw lets attackers run code on Adobe XD.
  • Confirm use and exposure of this design tool.
  • Assess if this tool is relevant to our environment.

Attack Path

How an attacker could exploit the issue

Adobe XD versions prior to 17.0.12 contain a path traversal vulnerability that could allow an attacker to execute arbitrary code. This vulnerability could be triggered if a user opens a specially crafted file.

  • No user interaction required.
  • User opens a malicious file.
  • Arbitrary code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe XD could allow an attacker to execute arbitrary code on a user's system when a crafted file is opened, potentially impacting the confidentiality, integrity, and availability of the affected system.

  • Arbitrary code execution on the user's system.
  • Opening a specially crafted file.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership for this vulnerability likely falls to application owners or IT support teams responsible for managing desktop software. The first practical step is to identify all systems with the affected application installed, assess business criticality, and then coordinate remediation, potentially requiring vendor engagement.

  • Identify and confirm application ownership.
  • Verify exposure and business criticality.
  • Plan phased deployment or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe XD?

Adobe XD is a desktop-based software application primarily used by designers to create prototypes and user interfaces for websites and mobile applications. Unlike server-side software that runs on centralized infrastructure, it functions as a client-side tool installed directly on individual user workstations.

What does path traversal mean in CVE-2019-7106?

Path traversal, classified as CWE-22, is a weakness where software improperly handles file paths. In this vulnerability, the application fails to restrict file access correctly, allowing a specially crafted file to bypass standard security boundaries and potentially execute unauthorized code on the host system.

How is this vulnerability triggered?

The flaw is triggered when the application processes a specially crafted file designed to exploit the path traversal weakness. It is important to note that the vulnerability is tied to the opening or handling of these malicious files; it is not triggered by simply having the software installed or idle on a system.

Do I need to worry about network access to this bug?

According to Halo Surface Signal, this software is a desktop application rather than a network-accessible service. Because it lacks a public-facing attack surface like a server or gateway, the risk is typically localized to the individual workstation rather than being exposed to remote internet-based attacks.

How should I respond if I have this software?

Start by identifying all workstations where Adobe XD is installed. Check the version number to see if it falls within the affected range, and prioritize updating to version 17.0.12 or later. Coordinate with your IT or desktop support teams to manage the deployment of these updates across your organization.

References