Impact
Premiere Pro suffers from an out-of-bounds write that enables arbitrary code execution when a malicious file is opened. The vulnerability is a CWE‑787 memory safety flaw that can overwrite critical memory structures, potentially allowing an attacker to run arbitrary code as the current logged‑in user if they successfully trigger the write. Because the vulnerability requires the user to open a crafted media file, exploitation is limited to scenarios where the victim opens the file.
Affected Systems
Adobe’s Premiere Pro is the impacted product. Specific affected versions are not listed in the advisory, so all installations of Premiere Pro should assume exposure until a patch status update is published.
Risk and Exploitability
The CVSS score of 7.8 marks it as a high‑severity flaw, yet the EPSS score of less than 1% indicates a very low exploitation probability under current threat landscape. It is not catalogued in CISA’s KEV list, further suggesting limited active exploitation. Attackers would need to deliver a malicious file that the user opens, so remote exploitation without user interaction is not viable. In environments where untrusted media is commonly opened, the risk of privilege escalation and compromise is significant.
OpenCVE Enrichment