Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-21594
7.8HIGH
Summary
Adobe InCopy versions 18.0 and earlier, including 17.4 and earlier, are prone to a Heap-based Buffer Overflow vulnerability. This weakness could allow an attacker to execute arbitrary code in the context of the current user. Successful exploitation necessitates user interaction, specifically requiring the victim to open a specially crafted malicious file. Users are urged to be cautious and follow security guidelines to mitigate the risk associated with this flaw.
Affected Version(s)
InCopy <= 18.0
InCopy <= 17.4
InCopy <= unspecified
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database