Impact
The vulnerability lies in Adobe Lightroom Classic’s handling of serialized data. When the application deserializes content provided by an untrusted source, it can trigger arbitrary code execution within the context of the user’s account. An attacker who supplies a crafted file can achieve full compromise of that user’s machine, including data loss, tampering, or persistence. The flaw is classified as CWE‑502 and the associated CVSS score of 8.6 highlights a high severity.
Affected Systems
It affects Adobe Lightroom Classic across all affected releases, although specific version numbers are not disclosed in the advisory. Users who continue to run legacy or unpatched copies of Lightroom Classic remain vulnerable until the security update is applied.
Risk and Exploitability
Exploitation requires the victim to open a malicious file, implying a user‑interaction attack. The CVSS score of 8.6 indicates that the weakness is exploitable even with limited privileges. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits code execution, the risk remains significant, especially in environments where users handle externally sourced images.
OpenCVE Enrichment