CVE-2025-43545

HIGH

Adobe Bridge < 14.1.7 - Arbitrary Code Execution via Uninitialized Pointer Access

Title source: llm
STIX 2.1

Description

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0028
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-824
Status published
Products (1)
adobe/bridge 14.0.0 - 14.1.7
Published May 13, 2025
Tracked Since Feb 18, 2026