First published: Thu Sep 10 2020(Updated: )
Adobe FrameMaker version 2019.0.6 (and earlier versions) lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This could be exploited to execute arbitrary code with the privileges of the current user. User interaction is required to exploit this vulnerability in that the target must open a malicious FrameMaker file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Framemaker | <=2019.0.6 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9725 is a vulnerability in Adobe FrameMaker version 2019.0.6 and earlier that allows arbitrary code execution.
CVE-2020-9725 can be exploited by providing user-supplied data with improper length validation, allowing an attacker to execute arbitrary code with the privileges of the current user.
CVE-2020-9725 is rated as high severity with a CVSS score of 7.8.
Adobe FrameMaker version 2019.0.6 and earlier versions are affected by CVE-2020-9725.
No, Microsoft Windows is not affected by CVE-2020-9725.
To fix CVE-2020-9725, users should update Adobe FrameMaker to the latest version.