Impact
The vulnerability is an out‑of‑bounds write (CWE‑787) that allows a malicious file to overwrite memory, which can lead to arbitrary code execution when that file is opened by a user of Adobe Audition. The primary consequence is execution of arbitrary code in the context of the current user. The specific impact on confidentiality, integrity, and availability is not explicitly stated, but such code execution could potentially allow compromise of those aspects.
Affected Systems
Adobe Audition is the affected product. Specific vendor and product names are Adobe:Audition. No version information is provided in the data, so it is unclear which releases contain the flaw; administrators should assume all publicly released versions could be at risk until a vendor statement is available.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires the victim to open a malicious file, which means the attack can be triggered only when the user interacts with the file. That is the only reported attack vector.
OpenCVE Enrichment