Impact
The vulnerability is an Incorrect Authorization flaw in the Adobe Genuine Software Integrity Service that allows an attacker to bypass security checks and gain unauthorized limited write access. This security feature bypass can be achieved without user interaction, but the attacker must have local or remote SMB access to the target desktop system. If exploited, the attacker could write to protected files or components controlled by the service, thereby compromising the integrity of the system.
Affected Systems
Adobe Genuine Software Integrity Service, distributed by Adobe, is affected. No specific version information is provided, so all installations of the service may be vulnerable.
Risk and Exploitability
The CVSS score of 4 indicates a low severity classification. The EPSS score is less than 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known public exploitation. Because the flaw requires local or SMB-access, the attack vector involves a local or remote attacker executing a crafted action that causes the service to write without proper authorization. No network exposure is required beyond SMB. Only an attacker who has local or remote SMB access to the machine where the service runs can exploit this vulnerability.
OpenCVE Enrichment