Executive brief
Adobe Bridge, a professional asset management application, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or full system compromise.
Technical details
Adobe Bridge is vulnerable to an Untrusted Search Path (CWE-426) flaw. The application incorrectly handles the search path when loading external resources or libraries, allowing an attacker to place a malicious file (such as a DLL) in a location that the application searches before legitimate system directories. The attack vector is local but requires user interaction (UI:R), where a victim must open a malicious file provided by the attacker. Successful exploitation results in arbitrary code execution with the privileges of the current user and carries a Changed Scope (S:C) impact. The vulnerability is addressed in versions 15.1.7 and 16.0.6.
Affected products
- Adobe Bridge <= 15.1.6, <= 16.0.5
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched