Impact
The vulnerability is an Incorrect Authorization flaw that allows a local attacker to bypass the Adobe Genuine Software Integrity Service's security checks, gaining unauthorized limited write access to protected files and components. The attacker does not need user interaction, but must have local access to the machine where the service runs.
Affected Systems
Adobe Genuine Software Integrity Service, distributed by Adobe, is affected. No specific version information is provided, so all installations of the service may be vulnerable.
Risk and Exploitability
The CVSS score of 4 indicates a low severity classification. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known public exploitation. Because the flaw requires local access, the attack vector involves a local attacker executing a crafted action that causes the service to write without proper authorization. No network exposure is required. Only an attacker who has local access to the machine where the service runs can exploit this vulnerability.
OpenCVE Enrichment