CVE-2022-35675: Adobe FrameMaker SVG File Parsing Use-After-Free Remote Code Execution Vulnerability
Published Aug 11, 2022
·Updated
Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
Adobe Framemaker<=2019.0.8
Adobe Framemaker>=2020<=2020.0.4
Microsoft Windows
Remediation
Event History
Aug 11, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-35675?
The severity of CVE-2022-35675 is high with a severity value of 7.8.
2
Which versions of Adobe FrameMaker are affected by CVE-2022-35675?
Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by CVE-2022-35675.
3
What is the vulnerability type of CVE-2022-35675?
CVE-2022-35675 is a Use After Free vulnerability.
4
What is the potential impact of CVE-2022-35675?
CVE-2022-35675 could result in arbitrary code execution in the context of the current user.
5
How can CVE-2022-35675 be exploited?
Exploitation of CVE-2022-35675 requires user interaction in that a victim must open a malicious file.