Impact
Premiere Pro contains an improper input validation flaw that allows an attacker to craft data which bypasses internal security checks. Once this boundary is breached, the program can gain write access to protected files or directories, effectively elevating the attacker’s capability to alter or replace critical assets. The weakness is identified as CWE‑20, indicating that the root cause is failure to restrict input to valid ranges or formats. The impact is limited to the system process that runs Premiere Pro, but the ability to write to privileged locations can compromise the overall security stance of the machine.
Affected Systems
Adobe Premiere Pro installations are affected. The CNA lists the product as Adobe:Premiere with no explicit version exclusions; therefore all current releases are potentially vulnerable until Adobe releases a patch in Security Bulletin APSB26‑76.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1 % shows a very low current exploitation probability. The vulnerability does not require user interaction; it can be triggered by specially crafted input processed by the application. While exploitation is not yet reported as a known exploit and the vulnerability is not part of CISA’s KEV catalog, the scope change means that a successful attack could extend beyond the immediate application, potentially affecting configuration or shared resources. Given these factors, the risk profile remains moderate, but administrative action is recommended before exposure grows.
OpenCVE Enrichment