Impact
This vulnerability is a NULL Pointer Dereference that causes the application to crash, resulting in a denial‑of‑service. The flaw exists in Adobe Content Credentials components, and its exploitation does not require user interaction.
Affected Systems
Adobe: Content Credentials Command-Line Tool, Adobe: Content Credentials JS SDK, Adobe: Content Credentials Rust SDK. No version information is provided in the advisory; therefore the impact may apply to all released versions until a patch is available.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The description states no user interaction is required, so the likely attack vector is either remote or local exploitation via malformed input to the CLI or SDK. A practitioner should consider that the flaw can be triggered by an attacker supplying crafted data to the affected components, but no evidence of privilege escalation or data exfiltration is provided.
OpenCVE Enrichment