Impact
The vulnerability is an integer underflow in CAI Content Credentials, which can cause the application to crash, resulting in denial of service. An attacker could deliver crafted input that triggers the underflow, leaving the system unavailable to legitimate users. The flaw is a classic numeric boundary defect (CWE-191).
Affected Systems
Adobe’s C2PA Tool and the Adobe Content Credentials Rust SDK are affected. Specific affected versions are not disclosed in the advisory; administrators should verify the versions they are running against the latest patch when the vendor releases it.
Risk and Exploitability
The CVSS score is 6.2, indicating moderate severity. The EPSS score is not available, so we lack data on current exploitation frequency. The issue is not listed in CISA KEV, implying no publicly known active exploitation. Exploitation does not require user interaction, indicating that a remote or local attacker can trigger the crash by supplying crafted content; the likely attack vector is remote content processed by the application.
OpenCVE Enrichment