Impact
The vulnerability is a heap-based buffer overflow that can be triggered when a user opens a specially crafted file in Adobe Bridge. Exploiting the overrun allows arbitrary code execution with the privileges of the current user, potentially compromising data or the operating system. This weakness is categorized as CWE-122.
Affected Systems
Adobe Bridge versions 16.0.2, 15.1.4 and all earlier releases are vulnerable. Users of these products should verify the specific version they have installed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the exploitation requires user interaction – the victim must open a malicious file. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating that it may not be widely exploited yet.
OpenCVE Enrichment