Adobe Framemaker Under Attack: Heap-based Buffer Overflow Vulnerability Affects Users
CVE-2024-30288

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
16 May 2024

Summary

A vulnerability has been identified in Adobe Framemaker that manifests as a Heap-based Buffer Overflow, affecting versions 2020.5, 2022.3, and earlier releases. This security flaw could allow an attacker to execute arbitrary code within the privileges of the user running the program. Successful exploitation necessitates that the user interacts with the system by opening a specially crafted file. This interaction exposes users to potential security threats, emphasizing the importance of caution when handling files from untrusted sources. For more detailed information and mitigation steps, refer to the vendor advisory.

Affected Version(s)

Adobe Framemaker 0 <= 2022.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.