Impact
The vulnerability is an improper input validation flaw in Adobe's Content Credentials tool and SDK. It permits an attacker to craft inputs that bypass built‑in security checks, potentially leading to unauthorized write operations without any user interaction. The consequence is a loss of data integrity and possible further compromise if the attacker can modify critical configuration or code files.
Affected Systems
Adobe:Content Credentials Command-Line Tool and Adobe:Content Credentials Rust SDK are affected. No specific version range is provided, so all installations of these products are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, though the EPSS score is not available, making the exact exploit probability uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation. The likely attack vector is local or service‑level input to the command‑line tool or SDK, requiring no privileged user interaction.
OpenCVE Enrichment