Impact
Lightroom Classic contains an out‑of‑bounds write that can lead to arbitrary code execution when a user opens a malicious file. The flaw is a classic memory corruption vulnerability classified as CWE‑787. Because the exploit relies on a malicious file being opened, the attacker must have some level of user interaction, and the breach would occur in the context of the current user with whatever privileges that user holds.
Affected Systems
Adobe Lightroom Classic. No specific affected versions are provided in the data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is not available and the issue is not listed in the CISA KEV catalog, suggesting exploitation has not yet been reported in the wild. The attack vector depends on user interaction and requires opening a crafted file, meaning the threat is mitigated by careful file handling but still poses a significant risk where users are allowed to open unknown files.
OpenCVE Enrichment