Impact
An integer overflow or wraparound vulnerability exists in Adobe Bridge that could lead to arbitrary code execution in the context of the current user. The flaw is exploited when Bridge processes a maliciously crafted file that causes numeric bounds checking to overflow. If successfully triggered, the attacker can run arbitrary code with the rights of the user running the application.
Affected Systems
Adobe Bridge software from Adobe. Version information is not disclosed in the advisory, so all released versions of Adobe Bridge available at the time of this vulnerability are considered potentially affected until a patch is applied.
Risk and Exploitability
The CVSS base score is 7.8, indicating high severity. The EPSS score is less than 1%, implying a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that a victim open a malicious file in Adobe Bridge, so user interaction is a prerequisite. The likely attack vector is an adversary convincing the user to open a file that contains the overflow‑triggering payload, after which the attacker could gain arbitrary code execution with the victim’s privileges.
OpenCVE Enrichment