Impact
Premiere Pro is vulnerable to a server‑side request forgery that can allow an attacker to cause the application’s server to issue arbitrary HTTP requests. This flaw can be leveraged to perform privilege escalation and potentially write unauthorized data. Because the scope is changed, exploitation can affect system‑wide permissions beyond the original user privileges.
Affected Systems
Adobe Premiere is the impacted product. No specific affected version numbers are listed in the advisory, so all installed instances should be treated as vulnerable until a patch or update is applied.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation does not require user interaction, implying that a remote attacker could exploit the flaw from their own network or via the service’s exposed interface. Attackers may construct crafted requests that the server forwards, potentially accessing internal resources or escalating privileges.
OpenCVE Enrichment