Impact
Bridge is vulnerable to an out‑of‑bounds write flaw that can be triggered when the application processes a malicious file. The defect is a typical memory corruption issue (CWE‑787) that could allow an attacker to execute arbitrary code running with the privileges of the user who opens the file. The impact is that compromised users may be able to run malicious instructions on the target system.
Affected Systems
Adobe Bridge users are impacted. No distinct version range is disclosed in the advisory, so all currently installed releases of Adobe Bridge should be evaluated for susceptibility until a vendor patch is issued.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalogue, reinforcing that widespread active exploitation is not yet documented. The primary attack vector revolves around user‑initiated file opening; an adversary would need to entice a user to open a crafted file that, when parsed by Bridge, triggers the out‑of‑bounds write and subsequently gains execution control.
OpenCVE Enrichment