CVE-2022-34249: Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe InCopy vulnerability?
The vulnerability ID for this Adobe InCopy vulnerability is CVE-2022-34249.
What is the severity of CVE-2022-34249?
The severity of CVE-2022-34249 is high (CVSS score 7.8).
Which versions of Adobe InCopy are affected by CVE-2022-34249?
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by CVE-2022-34249.
How does CVE-2022-34249 impact the user?
CVE-2022-34249 could result in arbitrary code execution in the context of the current user.
How can CVE-2022-34249 be exploited?
Exploitation of CVE-2022-34249 requires user interaction in that a victim must open a malicious file.
Where can I find more information about CVE-2022-34249?
You can find more information about CVE-2022-34249 at the following link: https://helpx.adobe.com/security/products/incopy/apsb22-29.html