CVE-2023-21619: Adobe FrameMaker Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21619?
CVE-2023-21619 is an out-of-bounds write vulnerability in Adobe FrameMaker 2020 Update 4 (and earlier) and 2022 (and earlier) that could allow arbitrary code execution.
How does CVE-2023-21619 affect Adobe FrameMaker?
CVE-2023-21619 affects Adobe FrameMaker 2020 Update 4 (and earlier) and 2022 (and earlier) by allowing an attacker to execute arbitrary code in the context of the current user.
What is the severity of CVE-2023-21619?
The severity of CVE-2023-21619 is high with a CVSS score of 7.8.
How can CVE-2023-21619 be exploited?
Exploiting CVE-2023-21619 requires user interaction, where a victim must open a malicious file.
How can I mitigate CVE-2023-21619?
To mitigate CVE-2023-21619, users are advised to update to a patched version of Adobe FrameMaker.