Impact
Adobe Bridge contains an out‑of‑bounds write flaw that can be exploited to execute arbitrary code within the current user’s context. The vulnerability is classified as CWE‑787 and would allow a malicious actor to run arbitrary instructions on a system when a user opens a crafted file.
Affected Systems
The affected product is Adobe Bridge. No specific version information was provided in the advisory, but all installations of Bridge may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score for this issue is 7.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, meaning a victim must open a malicious file; an attacker could supply such a file via email, download, or physical media. If exploited, the attacker would gain the privileges of the current user and could compromise the host system or move laterally within a network.
OpenCVE Enrichment