Impact
A crafted file can trigger an out‑of‑bounds write in Adobe Bridge, giving an attacker the ability to run arbitrary code with the victim’s privileges. The flaw is exercised when a user opens a malicious file inside Bridge, which then performs the vulnerable memory write and can lead to code execution.
Affected Systems
All installations of Adobe Bridge that have not yet applied the vendor’s latest update are potentially vulnerable. Because the advisory does not list specific version numbers, the risk applies broadly to all Bridge users until the fix is installed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity issue. The EPSS score of less than 1% shows that, at present, the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction – a victim must open a malicious file – so the attack vector is user‑initiated local interaction. While the potential impact of a successful exploit is severe, the overall threat is constrained by the low probability of discovery and use.
OpenCVE Enrichment