Impact
An out‑of‑bounds read in Adobe Audition allows an attacker to read data beyond the bounds of a buffer, potentially leaking sensitive information that resides in process memory. This vulnerability is identified as CWE‑125, which indicates a defect that could expose confidential data rather than cause arbitrary code execution.
Affected Systems
Adobe Audition versions 25.3 and all earlier releases are impacted. Users running those versions on any platform supported by the product are at risk.
Risk and Exploitability
The score is moderate (CVSS 5.5) and the EPSS probability is less than one percent, suggesting that exploitation is rare at present. The vulnerability is not listed in CISA’s KEV catalog. Exploiting it requires the victim to open a malicious file, meaning user interaction is needed, which reduces the likelihood of automated attacks.
OpenCVE Enrichment