Impact
The vulnerability is an incorrect authorization flaw that permits a user to execute code as themselves, potentially compromising any data or processes managed under their account. By bypassing authorization checks, a malicious file can trigger arbitrary code execution, resulting in a full compromise of the current user’s environment.
Affected Systems
Adobe Dreamweaver Desktop versions 21.6 and earlier are affected. The flaw applies to installations on macOS and Windows systems.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction—the victim must open a malicious file—so the attack vector is local. Despite the low probability, the potential for arbitrary code execution warrants prompt remediation.
OpenCVE Enrichment