First published: Thu Aug 11 2022(Updated: )
Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe FrameMaker | <=2019.0.8 | |
Adobe FrameMaker | >=2020<=2020.0.4 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35674 is an out-of-bounds read vulnerability in Adobe FrameMaker versions 2019 Update 8 and 2020 Update 4, which could allow an attacker to read past the end of allocated memory.
CVE-2022-35674 affects Adobe FrameMaker versions 2019 Update 8 and 2020 Update 4, allowing an attacker to exploit the vulnerability by parsing a crafted file.
CVE-2022-35674 has a severity rating of 7.8 (high).
An attacker can leverage CVE-2022-35674 to execute malicious code or perform denial-of-service attacks.
No, Microsoft Windows is not vulnerable to CVE-2022-35674.