Impact
Premiere Pro versions 26.0.2, 25.6.4 and all earlier releases contain an out‑of‑bounds write that can let an attacker run arbitrary code in the context of the user who opens a malicious media file. The flaw occurs when the program processes improperly formatted media, allowing data to be written beyond the intended memory limits.
Affected Systems
Adobe Premiere Pro installers for versions 26.0.2, 25.6.4 and earlier on any supported platform are vulnerable. Any user who installs these versions is at risk until the Adobe security update is applied.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity, and the absence of an EPSS score means the likelihood of exploitation is unknown. Based on the description, it is inferred that because the issue requires user interaction — opening a crafted file — passive or remote exploitation is limited, but social engineering could trigger the vulnerability. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment