Adobe InCopy SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2022-38405
7.8HIGH
What is CVE-2022-38405?
Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Version(s)
InCopy <= 16.4.2
InCopy <= 17.3
InCopy <= unspecified