Impact
The vulnerability allows an attacker to trigger uncontrolled resource consumption, causing the application to exhaust CPU, memory or other system resources. This results in a denial‑of‑service condition in which the affected program becomes unavailable or unusable. The flaw is identified as a CWE‑400 resource exhaustion weakness and can be triggered without any user interaction.
Affected Systems
Adobe’s C2PA Tool and Adobe Content Credentials Rust SDK are impacted. No specific version information is supplied, so all releases of these products are susceptible until a patch is applied.
Risk and Exploitability
With a CVSS score of 7.5 the risk is considered high; the EPSS score is not provided and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, likely through crafted content or requests sent to the tool, since user interaction is not required. If exploited, the application will become unresponsive, potentially affecting services that depend on it.
OpenCVE Enrichment