Adobe Creative Cloud (Bridge and Format Plugins): Multiple Vulnerabilities
A BSI Warn- und Informationsdienst (WID): Schwachstellen-Informationen (Bürger Cert) ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
BSI alerts to multiple vulnerabilities in Adobe Creative Cloud (Bridge and Format Plugins) enabling arbitrary code execution with privilege escalation , patching or mitigation strategy should be prioritized given widespread deployment in design operations.
Description
Multiple vulnerabilities in Adobe Creative Cloud Bridge and Format Plugins allow attackers to execute arbitrary code and escalate privileges. Vulnerabilities stem from untrusted search paths (DLL hijacking), improper authorization checks, path traversal, out-of-bounds write operations, and heap-based buffer overflows. Some vulnerabilities require user interaction (e.g., opening a crafted file). These vulnerabilities have been publicly documented by the German Federal Office for Information Security (BSI) and are known.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 41.00
- vendor mismatch penalty
- 0.00
Path: operational