Impact
Media Encoder contains a stack-based buffer overflow that allows an attacker to execute arbitrary code when a user opens a crafted media file. The vulnerability can lead to execution of malicious code with the permissions of the current user, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is Adobe Media Encoder. No specific version numbers are provided in the advisory, so all releases of Adobe Media Encoder might be impacted until an official fix is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and requires user interaction – the victim must open a malicious file – which limits the attack surface. Nonetheless, the potential impact remains significant if an attacker successfully tricks a user into opening the file.
OpenCVE Enrichment