Impact
The vulnerability is an integer underflow that causes the C2PA toolkit and Content Credentials Rust SDK to crash when processing certain inputs, resulting in a denial‑of‑service condition. Exploitation does not require any user interaction, making it potentially exploitable by an unauthenticated attacker who can send crafted data to the affected application.
Affected Systems
Adobe C2PA Tool and Adobe Content Credentials Rust SDK are affected. No specific vulnerable versions are listed in the advisory, so all versions running these components should be evaluated for the presence of the flaw.
Risk and Exploitability
With a CVSS score of 6.2 the flaw is considered moderate severity. The EPSS score is not reported, and the vulnerability is not listed in CISA’s KEV catalog, which suggests limited known exploitation at this time. Because the attack does not require user interaction, a remotely reachable instance of the affected software could be abused to crash the application, potentially disrupting services or availability for users.
OpenCVE Enrichment