Impact
This vulnerability is an out-of-bounds write in Adobe Audition that can be abused to execute arbitrary code within the context of the current user. The flaw originates from improper memory bounds checking when processing audio files, allowing a crafted file to overwrite adjacent memory and overwrite control data. If exploited, the attacker could run arbitrary code, compromise data confidentiality, integrity, and availability for the affected user.
Affected Systems
Adobe Audition on all versions that have not received Adobe's security update. Specific affected versions are not listed in the advisory, so all installations prior to patching should be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the risk. The EPSS score of less than 1% suggests that exploitation is considered unlikely in the current threat environment, and it is not listed in the CISA KEV catalog. Nevertheless, the flaw requires user interaction: a victim must open a malicious audio file, which is a relatively low barrier in contexts where users frequently handle untrusted audio files. The risk remains significant due to the high impact of code execution and the relative ease of file-based delivery.
OpenCVE Enrichment