CVE-2022-34247: Adobe InDesign Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an Out-Of-Bounds Write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe InDesign vulnerability?
The vulnerability ID for this Adobe InDesign vulnerability is CVE-2022-34247.
What is the severity of CVE-2022-34247?
The severity of CVE-2022-34247 is high with a score of 7.8.
Which versions of Adobe InDesign are affected by CVE-2022-34247?
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by CVE-2022-34247.
What is the impact of CVE-2022-34247?
CVE-2022-34247 could result in arbitrary code execution in the context of the current user.
How can CVE-2022-34247 be exploited?
Exploitation of CVE-2022-34247 requires user interaction in that a victim must open a malicious file.
Where can I find more information about CVE-2022-34247?
You can find more information about CVE-2022-34247 on the Adobe website at https://helpx.adobe.com/security/products/indesign/apsb22-30.html.