Impact
The vulnerability is an integer underflow that allows the application to process a negative value through wraparound, causing allocation logic to fail and the program to crash. This leads directly to a denial-of-service condition where the affected software becomes unavailable to legitimate users. The weakness is identified as CWE-191.
Affected Systems
Adobe CAI Content Credentials versions 0.78.2, 0.7.0 and all earlier releases are affected. These versions are used to sign and verify content in Adobe applications that rely on the Content Authenticity SDK.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, but the exploit does not require user interaction, so an attacker could potentially trigger the failure from any vector that can send crafted input or configuration to the software. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying it has not yet been widely observed in the wild. Nonetheless, because it results in a program crash, any exploitation would immediately disrupt availability and should be treated with high priority.
OpenCVE Enrichment