CVE-2020-9725: FrameMaker File Parsing Stack-based Buffer Overflow
Adobe FrameMaker version 2019.0.6 (and earlier versions) lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This could be exploited to execute arbitrary code with the privileges of the current user. User interaction is required to exploit this vulnerability in that the target must open a malicious FrameMaker file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-9725?
CVE-2020-9725 is a vulnerability in Adobe FrameMaker version 2019.0.6 and earlier that allows arbitrary code execution.
How can CVE-2020-9725 be exploited?
CVE-2020-9725 can be exploited by providing user-supplied data with improper length validation, allowing an attacker to execute arbitrary code with the privileges of the current user.
What is the severity of CVE-2020-9725?
CVE-2020-9725 is rated as high severity with a CVSS score of 7.8.
What software versions are affected by CVE-2020-9725?
Adobe FrameMaker version 2019.0.6 and earlier versions are affected by CVE-2020-9725.
Is Microsoft Windows affected by CVE-2020-9725?
No, Microsoft Windows is not affected by CVE-2020-9725.
How can I fix CVE-2020-9725?
To fix CVE-2020-9725, users should update Adobe FrameMaker to the latest version.