CVE-2021-28596: Adobe FrameMaker PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Framemaker version 2020.0.1 (and earlier) and 2019.0.8 (and earlier) are affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28596?
CVE-2021-28596 is an Out-of-bounds Write vulnerability affecting Adobe Framemaker versions 2020.0.1 and earlier, as well as 2019.0.8 and earlier.
What is the severity of CVE-2021-28596?
CVE-2021-28596 has a severity rating of 7.8, which is considered critical.
How does CVE-2021-28596 affect Adobe Framemaker?
CVE-2021-28596 allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user by exploiting an Out-of-bounds Write vulnerability in Adobe Framemaker.
Which versions of Adobe Framemaker are affected by CVE-2021-28596?
CVE-2021-28596 affects Adobe Framemaker versions 2020.0.1 and earlier, as well as 2019.0.8 and earlier.
How can I fix CVE-2021-28596?
To fix CVE-2021-28596, it is recommended to update Adobe Framemaker to the latest version available, which addresses the Out-of-bounds Write vulnerability.