CVE-2022-35708: Adobe Bridge SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Sep 19, 2022
·Updated
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Bridge>=11.1<11.1.4
Adobe Bridge>=12.0<12.0.3
macOS
Microsoft Windows
Remediation
Event History
Sep 19, 2022
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Bridge vulnerability?
The vulnerability ID for this Adobe Bridge vulnerability is CVE-2022-35708.
2
What is the severity of CVE-2022-35708?
The severity of CVE-2022-35708 is high with a CVSS score of 7.8.
3
What is the affected version of Adobe Bridge?
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected.
4
What is the risk associated with this vulnerability?
This vulnerability could result in arbitrary code execution in the context of the current user.
5
Is user interaction required to exploit this vulnerability?
Yes, exploitation of this vulnerability requires user interaction in that a victim must open a malicious file.