Impact
The vulnerability is a stack-based buffer overflow that can be triggered by opening a malicious file in Adobe Bridge. Exploitation leads to arbitrary code execution in the context of the current user, giving an attacker the same privileges as the victim. The weakness involves improper bounds checking during file processing, corresponding to CWE‑121.
Affected Systems
Adobe Bridge installations are affected. No specific version information is disclosed in the advisory; any deployment of Adobe Bridge remains at risk until a patch that addresses the buffer overflow is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the vulnerability requires user interaction to be exploited. Because the EPSS score is not provided, the likelihood of exploitation cannot be quantified, but the presence of a buffer overflow and the need for a user to open a file implies that the attack surface is limited to users who permit opening potentially malicious content. The vulnerability is not listed in the CISA KEV catalog, yet it remains a serious risk due to the potential for privileged code execution.
OpenCVE Enrichment