Impact
An out-of-bounds write condition exists in Adobe Audition that can be triggered by opening a crafted file, allowing an attacker to overwrite memory and inject malicious code. The flaw is a classic buffer overflow identified as CWE‑787, leading to arbitrary code execution in the victim’s user context. This can compromise confidentiality, integrity, or availability of the affected system if the attacker successfully runs code with user privileges.
Affected Systems
Affected products are versions of Adobe Audition. No specific version information is provided in the advisory, meaning all releases of Audition remain susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % shows the likelihood of exploitation in the wild is very low at present. The vulnerability is not cataloged in CISA’s KEV list. The exploit requires user interaction to open a malicious media file, implying the attack vector is local file-based. If exploited, the attacker could execute code with the same privileges as the user, enabling data exfiltration or malware deployment.
OpenCVE Enrichment