Impact
Lightroom Classic is affected by an out‑of‑bounds write that allows an attacker to overwrite memory of the process when the user opens a crafted file, which can lead to arbitrary code execution in the context of the current user. The vulnerability is a classic buffer overflow (CWE‑787) that does not require elevated privileges to be abused. Attackers can trigger it only if a victim opens a malicious file, so it is user‑interaction‑dependent.
Affected Systems
Adobe Lightroom Classic. No specific affected version is listed in the CVE data, so all installations that have not applied the latest Adobe update may be vulnerable.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, suggesting limited publicly known exploit activity. Because execution requires a malicious file to be opened by a user, the practical risk is significant for users who frequently handle unknown files or trust file sharing without verification.
OpenCVE Enrichment