Impact
Media Encoder contains an out‑of‑bounds write that can be triggered when the program parses a specially crafted media file, resulting in a buffer overflow. An attacker who supplies such a file can cause the application to execute arbitrary code in the context of the user who opens it, potentially compromising the confidentiality, integrity, and availability of the system.
Affected Systems
Adobe Media Encoder is the affected product. All releases without the fix detailed in Adobe Security Bulletin APSb26‑72 are likely vulnerable; no specific version numbers are provided. The advisory does not list any particular releases that are unaffected.
Risk and Exploitability
The CVSS score of 7.8 places this vulnerability in the medium‑high severity range. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalogue. Exploitation requires the victim to open a malicious media file, so the attack vector is user interaction. Attackers would need to deliver the file via phishing, social engineering, or compromised media sharing channels.
OpenCVE Enrichment