Impact
The vulnerability is an out‑of‑bounds write in Adobe’s DNG SDK that can corrupt memory. If successfully triggered, the application will crash or become unresponsive, effectively denying service to the user.
Affected Systems
Adobe DNG Software Development Kit versions 1.7.1 2502 and earlier are affected. Any software that incorporates these SDK releases is susceptible, including desktop and mobile applications that use DNG image processing.
Risk and Exploitability
The CVSS score of 5.5 places the issue in the medium category, and no EPSS information is available. The vulnerability requires a victim to open a crafted DNG file, so local or social‑engineering attack vectors are needed. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation, but the attack could still impact environments where untrusted files are processed.
OpenCVE Enrichment