Impact
An out‑of‑bounds write flaw in Adobe Media Encoder allows an attacker to overwrite adjacent memory when the program processes a specially crafted file, potentially leading to arbitrary code execution in the context of the user who opens that file. This vulnerability is classified as CWE‑787 and presents a risk that an attacker who can embed a malicious media file within an email or other file exchange mechanism can gain control of the system on the victim’s machine.
Affected Systems
Adobe Media Encoder is impacted; vendor and product information is confirmed, but specific affected version numbers are not provided in the available data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for a local user interaction scenario. An EPSS score of less than 1% suggests that exploitation is rarely observed. The vulnerability is not in the CISA KEV catalog. Exploitation requires that a user opens a malicious file, so the likely vector is a file distributed via email, download, or other media sharing channels. Because the code executes with the user’s privileges, a successful exploit would allow an attacker to run arbitrary code, modify data, or further compromise the system.
OpenCVE Enrichment