Impact
Adobe Connect suffers from an Improper Input Validation flaw that can let an attacker run arbitrary code in the context of the user who accesses a crafted page. The vulnerability is triggered when a victim opens a maliciously constructed URL or interacts with a compromised web page, and the bug causes the scope to be altered, potentially allowing the attacker to gain privileges beyond the original user session.
Affected Systems
The flaw affects Adobe Connect desktop and the Adobe Connect Android Mobile App. No specific version numbers are provided, so all currently deployed installations without the latest patch are considered at risk.
Risk and Exploitability
With a CVSS base score of 9.3, the risk level is high. The EPSS score is unavailable, but the vulnerability is not yet listed in the CISA KEV catalog, indicating limited known exploitation. Exploitation requires user interaction, so the likelihood is reduced compared to automated attacks, but the impact—arbitrary code execution—remains severe if an adversary succeeds. The potential social engineering component underscores the need for user awareness and prompt patching.
OpenCVE Enrichment