Impact
Adobe Bridge contains an Untrusted Search Path flaw that can allow an attacker to execute arbitrary code with the privileges of the user who opens a malicious file. The weakness is a classic untrusted search path error classified as CWE‑426, and because the exploitation can result in system‑wide code execution, it escalates the security scope.
Affected Systems
The vulnerability affects Adobe Bridge installations. No specific version range is listed in the advisory data; users should consult the Adobe security bulletin for detailed version information and ensure the latest released version is installed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low, but non‑zero, probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to open a crafted file; the likely attack vector is user‑directed rather than network‑based, which is inferred from the need for user interaction. If executed, the flaw permits arbitrary code execution in the context of the current user, potentially compromising the entire system.
OpenCVE Enrichment