Impact
CAI Content Credentials contains an integer underflow that could cause a crash during processing. The flaw is a classic wrap‑around error in which signed or unsigned arithmetic produces an invalid state, leading the application to terminate unexpectedly. The result is a denial‑of‑service (DoS) condition, rendering the affected component unusable until restarted.
Affected Systems
Adobe’s Content Credentials Command-Line Tool, the JavaScript SDK, and the Rust SDK are all vulnerable. The attackability applies to all versions of these products that have not applied the patch referenced in Adobe’s advisory.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate risk, but the EPSS score of less than 1% suggests that the probability of exploitation in the wild is very low. The vulnerability requires no user interaction, implying that a remote attacker who can supply crafted input or trigger a parsing operation could exploit it. The lack of KEV listing indicates no confirmed widespread active exploitation so far.
OpenCVE Enrichment