Impact
A buffer overrun in Adobe Media Encoder allows a specially crafted file to cause an out‑of‑bounds write, which can be exploited to execute arbitrary code in the context of the user who opens the file. The flaw is triggered when the program parses the malicious file, following the vulnerability description that the impact is execution of malicious code with the victim’s permissions.
Affected Systems
The vulnerability affects all installations of Adobe Media Encoder that have not applied the latest security patch. No precise version ranges are provided, so any copy of the software prior to the vendor’s corrective update is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, yet the EPSS score of less than 1% suggests that real‑world exploitation is uncommon at this time. The issue is not listed in CISA’s KEV catalog. Because an attacker must convince a user to open a malicious file, likely vectors include phishing, social engineering, or drive‑by delivery. The combination of high impact with low exploitation probability still warrants timely remediation.
OpenCVE Enrichment