CVE-2022-35674: Adobe FrameMaker SVG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-35674?
CVE-2022-35674 is an out-of-bounds read vulnerability in Adobe FrameMaker versions 2019 Update 8 and 2020 Update 4, which could allow an attacker to read past the end of allocated memory.
How does CVE-2022-35674 affect Adobe FrameMaker?
CVE-2022-35674 affects Adobe FrameMaker versions 2019 Update 8 and 2020 Update 4, allowing an attacker to exploit the vulnerability by parsing a crafted file.
What is the severity of CVE-2022-35674?
CVE-2022-35674 has a severity rating of 7.8 (high).
How can an attacker leverage CVE-2022-35674?
An attacker can leverage CVE-2022-35674 to execute malicious code or perform denial-of-service attacks.
Is Microsoft Windows affected by CVE-2022-35674?
No, Microsoft Windows is not vulnerable to CVE-2022-35674.