CVE-2022-34250: Adobe InCopy Font Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Jul 15, 2022
·Updated
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe InCopy<=16.4.1
Adobe InCopy>=17.0<=17.2
macOS
Microsoft Windows
Event History
Jul 15, 2022
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-34250?
CVE-2022-34250 is a Heap-based Buffer Overflow vulnerability in Adobe InCopy.
2
What is the severity of CVE-2022-34250?
CVE-2022-34250 has a severity value of 7.8, which is considered high.
3
Which versions of Adobe InCopy are affected by CVE-2022-34250?
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by CVE-2022-34250.
4
How can CVE-2022-34250 be exploited?
Exploitation of CVE-2022-34250 requires user interaction, where a victim must open a malicious file.
5
Is Apple macOS or Microsoft Windows vulnerable to CVE-2022-34250?
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2022-34250.