Impact
The flaw is an out‑of‑bounds read within the Adobe DNG SDK, allowing an attacker to read memory that should not be accessible. This can lead to disclosure of sensitive data that resides in the process memory, such as credentials or other confidential information. The vulnerability is identified by CWE‑125 and is limited to memory exposure, not execution of arbitrary code.
Affected Systems
Adobe’s DNG SDK, versions 1.7.1 2502 and older, are vulnerable. Any installation of these SDK releases that processes DNG files may be impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a maliciously crafted DNG file, meaning user interaction is a prerequisite. While this limits automated attacks, the potential for sensitive data leakage remains a concern if users are tricked into opening such files.
OpenCVE Enrichment