PT-2022-6388 · Adobe · Bridge

Published

2022-09-22

·

Updated

2023-02-24

·

CVE-2023-21583

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Bridge versions 12.0.3 and earlier Adobe Bridge versions 13.0.1 and earlier
Description The issue is related to an out-of-bounds read vulnerability in Adobe Bridge, specifically when parsing embedded fonts. This could lead to the disclosure of sensitive memory. An attacker could exploit this vulnerability to bypass security mitigations such as Address Space Layout Randomization (ASLR). Exploitation requires user interaction, where a victim must open a malicious file.
Recommendations For Adobe Bridge versions 12.0.3 and earlier, update to a version later than 12.0.3 to resolve the issue. For Adobe Bridge versions 13.0.1 and earlier, update to a version later than 13.0.1 to resolve the issue. As a temporary workaround, consider avoiding the use of embedded fonts in Adobe Bridge until a patch is available.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-01139
CVE-2023-21583
ZDI-23-140

Affected Products

Bridge