Impact
Adobe Bridge contains a heap‑based buffer overflow that allows an attacker to write beyond a buffer boundary when processing a specially crafted file. The flaw can lead to arbitrary code execution in the context of the user running Bridge, representing a significant compromise of confidentiality, integrity, and availability. This is a memory corruption vulnerability classified as CWE‑122.
Affected Systems
Adobe Bridge releases 16.0.2, 15.1.4 and all earlier versions are affected. The issue can be triggered on any platform where these versions run by opening a malicious file.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. Exploitation requires a victim to open a malicious file, so user interaction is mandatory. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits yet. Nevertheless, the combination of high severity and a user‑interaction attack vector makes this a critical risk for environments where users handle untrusted files.
OpenCVE Enrichment