Impact
An integer overflow or wraparound in Adobe Content Credentials leads to a crash of the application, causing a denial‑of‑service condition. The flaw does not allow an attacker to gain unauthorized access or execute code, but it can terminate the affected component and prevent legitimate use.
Affected Systems
The vulnerability is present in Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK. No specific version information is supplied, so any installation of these components is potentially affected until an update is applied.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The issue is not listed in CISA’s KEV catalog. The description states that the vulnerability can be triggered without user interaction; the likely attack vector is when the component processes external or untrusted input, potentially via a remote or local interface, though the exact vector is not detailed.
OpenCVE Enrichment