Impact
Lightroom Classic contains an out‑of‑bounds write flaw that, when triggered by opening a specially crafted file, can overwrite memory beyond the intended bounds and lead to arbitrary code execution. The flaw allows the attacker to execute code with the privileges of the user who opens the file, potentially compromising confidential data, installing malware, or taking full control of the affected system. The weakness is identified as CWE‑787.
Affected Systems
Adobe Lightroom Classic on any installation where the vulnerability has not been patched. No specific version information is listed in the CNA data, so all releases that include the vulnerable component are considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is not reported, and the vulnerability is not listed in CISA KEV. Exploitation requires user interaction; a victim must open a malicious file. The likely attack vector is a social engineering scenario where the attacker sends a file that a user opens or where a user downloads an infected file. Given the lack of automated exploitation and the need for user action, the immediate threat is lower than high‑risk remotely exploitable bugs, but the impact remains significant if an employee opens a malicious file.
OpenCVE Enrichment