Impact
The vulnerability is an Improper Input Validation flaw, classified as CWE‑20, in Adobe CAI Content Credentials that allows an attacker to supply malformed input that causes the application to crash. The crash results in a denial‑of‑service for any service using the credentials component. No evidence is provided that the flaw leads to code execution, data disclosure, or privilege escalation, so the primary impact is loss of availability.
Affected Systems
Adobe CAI Content Credentials versions 0.78.2, 0.7.0, and all earlier releases are affected. Any system or application that incorporates these versions of the credentials component is vulnerable.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. Because the EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the likelihood of exploitation remains uncertain, although the description states that no user interaction is required. This implies that an attacker could trigger the crash remotely, potentially using crafted network input or a web request. Until a patch is applied, the risk is moderate but could become severe if the flaw is actively abused.
OpenCVE Enrichment