Impact
An out-of-bounds write flaw in Adobe Audition permits an attacker to execute arbitrary code in the context of the user who opens a malicious file. The weakness results in a potential loss of confidentiality, integrity, and availability of the victim’s system due to the ability to run code with the user’s privileges.
Affected Systems
All installations of Adobe Audition may be affected, as the advisory does not list a specific product or version range. Any user who has not applied the latest Adobe update should verify whether their product contains the fix referenced in the Adobe security bulletin and plan to update accordingly.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1% indicates that exploitation is not common yet but remains possible. Because the flaw requires the victim to open a malicious file, social engineering or deceptive attachments represent the likely attack vector. The vulnerability is not listed in the CISA KEV catalog, but administrators should treat it as a high‑risk issue and prioritize patch deployment.
OpenCVE Enrichment