Impact
Bridge versions 15.1.2, 16.0 and earlier are affected by a heap-based buffer overflow that can lead to arbitrary code execution in the context of the current user. The flaw arises when a specially crafted file is processed, allowing the attacker to overwrite heap memory and execute arbitrary code.
Affected Systems
Affected versions of Adobe Bridge include 15.1.2, 16.0, and all earlier releases for both Windows and macOS operating systems.
Risk and Exploitability
The flaw carries a CVSS score of 7.8, indicating high severity, but the EPSS score is below 1%, implying low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, namely opening a malicious file, so attack vector is local. Successful exploitation would allow attackers to run code with the victim’s privileges.
OpenCVE Enrichment