Impact
Adobe Bridge versions 15.1.3, 16.0.1 and earlier contain an integer overflow or wraparound flaw that can be triggered by opening a specially crafted file, allowing an attacker to execute arbitrary code in the context of the current user. The vulnerability directly compromises confidentiality, integrity, and availability of the affected system by giving the attacker the same privileges as the victim user.
Affected Systems
Adobe Bridge on macOS and Windows platforms is affected. The flaw applies to Bridge versions 15.1.3, 16.0.1 and all earlier releases. Users deploying these versions on Apple macOS or Microsoft Windows should be aware that the vulnerability spans both operating systems.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, yet the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires user interaction; a victim must open a malicious file for the integer overflow to occur. Once triggered, the attacker can run code with the victim’s privileges. The combination of high severity and user‑interaction launch means that mitigation via patching is imperative to prevent potential compromise.
OpenCVE Enrichment