Impact
Adobe Bridge suffers from an Incorrect Authorization flaw that can be triggered when a user opens a specially crafted file. The vulnerability allows a malicious file to bypass the expected access controls and execute arbitrary code with the privileges of the current user, and the scope of the vulnerability is changed.
Affected Systems
The affected product is Adobe Bridge. No specific version information was provided by the vendor, so any installation of Adobe Bridge that has not yet received the vendor’s security update can be assumed vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attacking this flaw requires user interaction—namely, the victim must open a malicious file—so the risk also depends on user caution. Once executed, the attacker runs code in the user’s context, providing the potential for system‑wide compromise if the user has elevated privileges.
OpenCVE Enrichment