Impact
Adobe Audition is vulnerable to an out‑of‑bounds write that occurs while parsing a specially crafted media file. The flaw allows an attacker to corrupt memory during file decoding, which can lead to arbitrary code execution in the user’s context. This is a classic type of buffer overflow defect identified as CWE‑787.
Affected Systems
Adobe Audition is affected. Because no specific version range is provided in the CNA data, every currently installed release of Audition should be considered vulnerable until an update is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. EPSS is below 1 %, so active exploitation is unlikely but not impossible. The issue is not listed in CISA’s KEV catalogue, suggesting no widespread attacks have been observed. Exploitation requires the victim to open a malicious file, making it a user‑interactive local file exploit that can compromise systems only when the software is running.
OpenCVE Enrichment