Impact
An out‑of‑bounds write flaw within Adobe Bridge permits an attacker to run arbitrary code in the context of the user who opens a crafted file. This flaw can compromise confidentiality, integrity, and availability by allowing the execution of malicious code with the victim’s privileges.
Affected Systems
Adobe Bridge produced by Adobe is affected; the vulnerability applies to all current releases prior to the fix stated in the Adobe security bulletin linked in the references.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is high severity, yet the EPSS score is under 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and an attacker must persuade a user to open a malicious file, making user interaction a prerequisite for exploitation.
OpenCVE Enrichment