Impact
Bridge is affected by a heap‑based buffer overflow that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when the user opens a specially crafted file created by an attacker. Because the code runs with the victim’s privileges, the attacker can take control of the system or install further malware.
Affected Systems
Adobe Bridge on unsupported or unpatched versions of the software. The affected product is Adobe Bridge, with no specific version range listed in the advisory, so all versions released before the patch are considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 places the vulnerability in the high severity range, but the EPSS score of less than 1% indicates a very low overall exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, so it is a user‑interaction model of attack and is less likely to be leveraged remotely, but still represents a significant risk if users accidentally process compromised documents.
OpenCVE Enrichment