Impact
A heap‑based buffer overflow can lead to arbitrary code execution in the context of the user. The flaw allows attacker control over program flow, compromising confidentiality, integrity, or availability of the affected system. The vulnerability is classified as CWE‑122.
Affected Systems
Adobe Bridge versions 16.0.2, 15.1.4, and earlier are affected. Vulnerable builds are listed under Adobe Bridge in the CNA vendor/product list.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. Exploitation requires user interaction, as the affected user must open a malicious file. EPSS data is unavailable and the vulnerability is not part of the CISA KEV catalog, suggesting that while the risk is moderate, the likelihood of widespread exploitation remains dependent on user behavior.
OpenCVE Enrichment