Impact
The vulnerability is an uncontrolled recursion that can cause a stack overflow and, if triggered, allows an attacker to execute arbitrary code in the context of the current user. As a result, confidentiality, integrity, and availability of the affected system can be compromised. The weakness is classified as CWE‑674.
Affected Systems
Adobe Bridge applications of all released versions are potentially affected; specific version information is not specified in the advisory. The flaw applies to all platforms supported by Adobe Bridge, including Windows and macOS.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires the victim to open a maliciously crafted file, so a social engineering or phishing scenario is the likely attack vector.
OpenCVE Enrichment