Impact
Adobe Bridge is vulnerable to an out‑of‑bounds write that could result in arbitrary code execution in the context of the current user. The flaw originates from insufficient bounds checking when parsing certain input data from a file, and successful exploitation would allow an attacker to gain full control of affected systems, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability applies to Adobe Bridge for all supported operating systems. The affected product is Adobe Bridge; specific affected versions are not listed in the public data and should be cross‑checked against Adobe’s advisory for the latest fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is below 1 %, suggesting that, at present, the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Because an attacker must trick a user into opening a crafted file, the attack vector is user‑interaction‑dependent; however, once executed, the code runs with the user’s rights.
OpenCVE Enrichment