Impact
Adobe Content Credentials, including the C2PA Tool and the Rust SDK, contains an integer underflow vulnerability that can cause the application to crash when malformed input is processed, resulting in a denial-of-service condition. The flaw allows an attacker to trigger a wraparound in signed or unsigned arithmetic during credential verification, leading to an abrupt application termination. This impact is purely availability loss; confidentiality or integrity are not directly compromised.
Affected Systems
The vulnerability impacts Adobe’s C2PA Tool and the Adobe Content Credentials Rust SDK. No specific affected versions are listed, so all installations of these products remain potentially vulnerable until a patch is applied or the feature is disabled.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity issue. Exploitation does not require user interaction, and the attack can be performed remotely by providing crafted credential data to the affected process. While the EPSS score is currently unavailable, the absence of KEV listing suggests no known active exploitation. Nevertheless, the high severity makes timely mitigation important.
OpenCVE Enrichment