Adobe InCopy Improper Input Validation Remote Code Execution Vulnerability
CVE-2023-21596
7.8HIGH
Summary
Adobe InCopy versions 18.0 and 17.4 and earlier are compromised by an improper input validation flaw. This vulnerability allows for arbitrary code execution within the user’s context, provided a user opens a specially crafted malicious file. Attackers exploiting this vulnerability would need user interaction, highlighting the importance of caution when handling unknown documents.
Affected Version(s)
InCopy <= 18.0
InCopy <= 17.4
InCopy <= unspecified
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database