Impact
Audition contains an out‑of‑bounds read that can expose sensitive in‑memory data. The flaw allows an attacker to read bytes beyond the intended buffer limits, potentially leaking private data and thereby revealing confidential information.
Affected Systems
The product impacted is Adobe Audition. No specific version numbers are provided in the advisory, so any installation of Adobe Audition could be vulnerable until a patched release is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% signals a very low current exploitation probability. This vulnerability is not part of the CISA KEV catalog. An attacker would need the victim to open a crafted malicious file, so the attack vector is user interaction, typically via an accidentally imported file or otherwise opened document in Audition.
OpenCVE Enrichment