First published: Tue Jul 09 2024(Updated: )
Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Bridge CC | <13.0.8 | |
Adobe Bridge CC | >=14.0.0<14.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34139 has a high severity as it involves an Integer Overflow vulnerability that could lead to arbitrary code execution.
To mitigate CVE-2024-34139, upgrade Adobe Bridge to version 14.1.1 or later, or 13.0.8 if using an earlier version.
CVE-2024-34139 affects Adobe Bridge versions 14.0.4, 13.0.7, 14.1, and earlier.
CVE-2024-34139 is classified as an Integer Overflow or Wraparound vulnerability.
Yes, exploitation of CVE-2024-34139 requires user interaction, such as opening a malicious file.