Impact
The vulnerability is an Improper Input Validation flaw (CWE-20) that allows an attacker to corrupt the processing of user-supplied input within the Adobe Content Credentials components. When exploited, the application can crash, leading to a denial-of-service scenario that disrupts availability for legitimate users or services relying on the tool.
Affected Systems
Adobe Content Credentials Command-Line Tool and Adobe Content Credentials Rust SDK are the affected products. No specific version information is listed, so all installed instances of these components are potentially vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS score of 5.5, the severity is moderate, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, but the attack requires user interaction such as opening a malicious URL or visiting a compromised web page, indicating that successful exploitation depends on targeted phishing or social engineering attempts. Because the flaw results only in service disruption, the impact is limited to availability rather than data integrity or confidentiality.
OpenCVE Enrichment