Impact
Media Encoder is vulnerable to an out‑of‑bounds read that enables an attacker to access memory that was not intended to be visible outside the application, consistent with CWE‑125. This flaw can expose sensitive data that resides in memory during the file‑processing routine, potentially leaking confidential information to the attacker.
Affected Systems
Adobe Media Encoder is the sole affected product. The CNA lists Adobe as the vendor, but the advisory does not specify which releases are impacted, so any unpatched installation is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk level. An EPSS score of less than 1% suggests that large‑scale exploitation is unlikely, yet an attacker could target specific users. The vulnerability is not listed in CISA KEV. Exploitation requires the victim to interact with a malicious media file, so the attack vector is file‑based and user‑initiated.
OpenCVE Enrichment