Impact
Adobe Premiere Pro is affected by an out‑of‑bounds write that can be triggered when a user opens a specially crafted media file. The flaw allows an attacker to write arbitrary data beyond the intended memory bounds, leading to control‑flow hijacking and execution of malicious code in the context of the victim user.
Affected Systems
Affected products are Adobe Premiere Pro. The public data does not list specific version numbers, so all current releases may be susceptible until an official fix is applied. Users should verify which version they are running against Adobe’s advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of <1% suggests a low probability of real‑world exploitation at present. The vulnerability is not included in CISA’s KEV catalog. Because exploitation requires the user to open a malicious file, the attack vector is user interaction, but once executed an attacker can achieve arbitrary code execution.
OpenCVE Enrichment