Impact
Bridge contains an untrusted pointer dereference flaw that can lead to arbitrary code execution in the user’s context. The vulnerability is caused by the application dereferencing a pointer derived from untrusted input when processing a file, allowing an attacker to craft a malicious file that triggers the unsafe operation. Successful exploitation would provide the attacker with the privileges of the user who opens the file.
Affected Systems
Adobe Bridge is affected. The advisory lists Adobe Bridge as the impacted product, but no specific version numbers are provided; therefore all versions of Adobe Bridge that fall under the scope of the Adobe security advisory are potentially at risk until a vendor patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests that known exploitation is very unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to open a specially crafted file, so the attack vector involves user interaction, typically through social engineering or accidental file download. The overall risk is moderate, with high impact if the flaw is exploited, but limited by the need for the user to intentionally launch the malicious file.
OpenCVE Enrichment