Impact
Lightroom Classic contains an out‑of‑bounds write flaw that allows an attacker to execute arbitrary code with the privileges of the user who opens a crafted file. The weakness is a classic buffer overflow (CWE‑787) exposed when parsing maliciously formed data inside a Lightroom image or catalog file. If exploited, any code the attacker injects would run with the victim’s account rights, potentially giving full control over the system for that user. The vulnerability is not a denial‑of‑service flaw, but a full code‑execution risk that can lead to data compromise or further lateral movement.
Affected Systems
The affected product is Adobe Lightroom Classic, as listed by the vendor and CNA. All builds of Lightroom Classic prior to the release that contains the out‑of‑bounds write fix are vulnerable. Specific version information is not disclosed in this advisory, so administrators should refer to Adobe’s security bulletin for the precise patch version. Currently, only the Adobe product is listed; no other third‑party software is impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. Exploitation requires user interaction – the victim must open a malicious file – meaning the attack vector is user‑initiated with a local attack model. Because the EPSS score is not available, a precise probability of exploitation cannot be derived, but the lack of a public KEV listing suggests no known widespread attacks yet. Nonetheless, the combination of high impact and the ease of triggering by opening a file makes it a serious risk for environments where users ingest untrusted media.
OpenCVE Enrichment