Adobe InCopy Improper Input Validation Remote Code Execution Vulnerability
CVE-2023-21596

7.8HIGH

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
13 January 2023

Summary

Adobe InCopy versions 18.0 and 17.4 and earlier are compromised by an improper input validation flaw. This vulnerability allows for arbitrary code execution within the user’s context, provided a user opens a specially crafted malicious file. Attackers exploiting this vulnerability would need user interaction, highlighting the importance of caution when handling unknown documents.

Affected Version(s)

InCopy <= 18.0

InCopy <= 17.4

InCopy <= unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.