Impact
Lightroom Classic is affected by an out‑of‑bounds write flaw that, if triggered, can allow a malicious file to overwrite memory beyond its bounds. This can lead to arbitrary code execution in the context of the user who opens the file, as the vulnerability triggers during file import. The weakness is a classic buffer overflow problem identified as CWE‑787.
Affected Systems
The affected product is Adobe Lightroom Classic. No specific release or version numbers are disclosed in the advisory, so any installation of Lightroom Classic that predates the security update is potentially vulnerable. Users should refer to the Adobe Security Advisory for the list of impacted versions and patch guidance.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as High severity. EPSS is not available, but the absence of a publicly known exploit and the requirement of user interaction reduce the immediate likelihood of exploitation. The flaw is not listed in CISA KEV, indicating no confirmed active exploitation as of the last assessment. Nevertheless, because the exploit path involves opening a crafted file, the attack vector is local; a malicious actor would need to provide the user with a specially crafted Lightroom file and convince them to open it.
OpenCVE Enrichment