Impact
The vulnerability is an Integer Underflow (Wrap or Wraparound) (CWE-191) that can crash the application. An attacker can trigger a denial-of-service condition without any user interaction, causing the affected processes to terminate unexpectedly. The impact is loss of availability for applications that rely on the affected content credentials components.
Affected Systems
Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version information is provided.
Risk and Exploitability
The CVSS score of 6.2 indicates a medium severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. As exploitation does not require user interaction, the attack vector is inferred to be remote or local via the application components’ interfaces. If an attacker can augment input to cause an integer underflow, the application will crash, producing a denial-of-service.
OpenCVE Enrichment