Impact
Lightroom Classic has an out‑of‑bounds write that allows an attacker to run code with the privileges of the user. The flaw is triggered when the application processes a specially crafted file, potentially enabling arbitrary instruction execution. The impact is execution of arbitrary code in the user context.
Affected Systems
Adobe Lightroom Classic is affected; all installations that have not applied the security update released in the Adobe advisory remain vulnerable. The advisory does not list specific version numbers, so any unpatched installation is considered impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction – a victim must open a malicious file – so the attack can only occur when the user receives or opens a file that the attacker can control. While no public exploit is known, a determined adversary could craft a file to exploit the flaw.
OpenCVE Enrichment