Impact
An uncontrolled resource consumption flaw in Adobe Content Credentials allows an attacker to exhaust system resources, causing the affected application to become unresponsive. The vulnerability does not require user interaction and can be leveraged by simply sending specially crafted input or requests to the affected components, leading to a denial of service condition. The primary impact is loss of availability for the services that rely on the Content Credentials tool, JS SDK, or Rust SDK.
Affected Systems
The vulnerability affects Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript Software Development Kit, and Adobe Content Credentials Rust Software Development Kit. No specific product versions are cited in the available information, so all current instances of these components should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score of less than 1% suggests that, although the flaw could be highly damaging if exploited, it is unlikely to be actively targeted or exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating low immediate threat. Nonetheless, because exploitation does not require user interaction, an attacker could trigger it from a remote location, leading to a denial of service of the entire application.
OpenCVE Enrichment