Impact
Lightroom Classic is vulnerable to an out‑of‑bounds write that can be triggered by malicious input files. The flaw can be exploited to execute arbitrary code with the privileges of the user who opens the file, potentially compromising system or application integrity and allowing further lateral movement.
Affected Systems
Adobe Lightroom Classic instances are affected. No specific version ranges are provided, so any deployment using a pre‑patch copy may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, indicating that user interaction is necessary for successful attack. The risk is therefore moderate to high for environments where users routinely open unknown or unverified photos or catalogs.
OpenCVE Enrichment