ZDI-CAN-22653: ZDI-24-291: Adobe Bridge PS File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-20752.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22653?
The severity of ZDI-CAN-22653 is rated as 7 on the CVSS scale, indicating a high security risk.
How do I fix ZDI-CAN-22653?
To fix ZDI-CAN-22653, ensure that you update Adobe Bridge to the latest version provided by Adobe that addresses this vulnerability.
What kind of attack does ZDI-CAN-22653 allow?
ZDI-CAN-22653 allows remote attackers to execute arbitrary code on affected installations of Adobe Bridge.
Is user interaction required to exploit ZDI-CAN-22653?
Yes, user interaction is required for ZDI-CAN-22653 because the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-22653?
ZDI-CAN-22653 specifically affects Adobe Bridge CC installations.