CVE-2023-21599: Adobe InCopy Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21599?
CVE-2023-21599 is a vulnerability in Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) that allows an attacker to read sensitive memory and bypass mitigations.
How severe is CVE-2023-21599?
CVE-2023-21599 has a severity rating of 5.5, which is considered medium.
How does CVE-2023-21599 affect Adobe InCopy?
CVE-2023-21599 affects Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) by allowing an attacker to read sensitive memory and bypass certain security measures like ASLR.
How can an attacker exploit CVE-2023-21599?
Exploitation of CVE-2023-21599 requires user interaction, but an attacker can leverage this vulnerability to read sensitive memory and potentially disclose sensitive information.
How can I fix CVE-2023-21599?
To fix CVE-2023-21599, it is recommended to update Adobe InCopy to a version that is not affected by this vulnerability.