Impact
Lightroom Classic includes an integer overflow or wraparound flaw that allows arbitrary code execution when a malicious file is opened. The flaw is identified as CWE‑190. Exploitation requires the victim to interact with the file, meaning the code runs with the privileges of the current user.
Affected Systems
Adobe Lightroom Classic is affected. No specific product versions are listed; the advisory does not provide version ranges, so all installations of Lightroom Classic remain potentially vulnerable until patched or otherwise secured.
Risk and Exploitability
The CVSS score of 7.8 demonstrates a high severity impact. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exfiltration or sabotage could proceed if a user opens a crafted file, but exploitation requires the user to interact with the file, limiting the attack surface to social‑engineering or compromised media scenarios.
OpenCVE Enrichment