ZDI-CAN-24057: ZDI-24-1139: Adobe Bridge AVI FIle Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-39386.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24057?
The ZDI-CAN-24057 vulnerability has been assigned a CVSS rating of 7, indicating it is critical.
How do I fix ZDI-CAN-24057?
To fix ZDI-CAN-24057, ensure that you update Adobe Bridge to the latest version provided by Adobe.
What type of attackers can exploit ZDI-CAN-24057?
ZDI-CAN-24057 can be exploited by remote attackers who trick users into visiting malicious pages or opening harmful files.
What software is affected by ZDI-CAN-24057?
ZDI-CAN-24057 affects Adobe Bridge CC installations.
What is required for an attack to succeed with ZDI-CAN-24057?
User interaction is required for ZDI-CAN-24057 as the target must visit a malicious page or open a malicious file.