CVE-2022-28835: Adobe InCopy Font Parsing Use-After-Free Remote Code Execution Vulnerability
Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28835?
CVE-2022-28835 is a Use-After-Free vulnerability in Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) that could result in arbitrary code execution.
How does CVE-2022-28835 affect Adobe InCopy?
CVE-2022-28835 affects Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) by allowing arbitrary code execution in the context of the current user.
Is user interaction required to exploit CVE-2022-28835?
Yes, exploitation of CVE-2022-28835 requires user interaction in that a victim must open a malicious file.
How severe is the vulnerability CVE-2022-28835?
The severity of CVE-2022-28835 is high, with a CVSS severity score of 7.8.
How can I mitigate the vulnerability in Adobe InCopy?
To mitigate the vulnerability in Adobe InCopy, it is recommended to update to the latest version provided by Adobe.