Adobe InCopy Out-of-Bounds Read Vulnerability v1.0
CVE-2023-26368

7.8HIGH

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
16 November 2023

Summary

Adobe InCopy is susceptible to an out-of-bounds read vulnerability that occurs when processing specially crafted files. This flaw allows attackers to read beyond the allocated memory structures, potentially leading to the execution of arbitrary code within the context of the user running the software. For the exploitation of this vulnerability to succeed, user interaction is necessary, requiring the victim to open a maliciously crafted file. It is crucial for users to remain vigilant against such threats by ensuring that they do not open untrusted files.

Affected Version(s)

InCopy 0 <= 17.4.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.