PT-2024-8564 · Adobe · Bridge

Published

2024-07-09

·

Updated

2024-08-02

·

CVE-2024-34139

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Bridge versions 14.1 and earlier Adobe Bridge versions 14.0.4 Adobe Bridge versions 13.0.7
Description The issue is related to an Integer Overflow or Wraparound that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, where a victim must open a malicious file. The vulnerability is associated with a file manager component.
Recommendations For Adobe Bridge versions 14.1 and earlier, update to a version that fixes the Integer Overflow or Wraparound issue. For Adobe Bridge versions 14.0.4, update to a version that fixes the Integer Overflow or Wraparound issue. For Adobe Bridge versions 13.0.7, update to a version that fixes the Integer Overflow or Wraparound issue. As a temporary workaround, consider avoiding the use of file manager components that may trigger the Integer Overflow or Wraparound until a patch is available.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-10133
CVE-2024-34139

Affected Products

Bridge