Impact
Lightroom Classic contains an improper limitation of a pathname to a restricted directory (Path Traversal) that permits an attacker to request arbitrary files from the file system. The flaw allows a victim to open a malicious file that references a pathname outside the designated directory, resulting in the read of sensitive files. Because the file must be opened by a user, the attack requires user interaction, and the vulnerability changes the scope of the application’s access rights.
Affected Systems
The vulnerability affects Adobe Lightroom Classic. No specific product versions are listed in the official advisory, so all installations of the software are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8.6 classifies it as a high severity flaw, though the EPSS score is unavailable, implying limited data on exploitation likelihood. It is not currently listed in CISA’s KEV catalog. Given that exploitation requires a user to open a crafted file, the risk is moderate in environments where users lack access to sensitive directories, but any exposure to untrusted files elevates the threat. Patch or updated version releases from Adobe are the primary mitigation, with additional controls recommended where immediate updates are not possible.
OpenCVE Enrichment