CVE-2023-21622: Adobe FrameMaker Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21622?
CVE-2023-21622 is an out-of-bounds write vulnerability in FrameMaker 2020 Update 4 (and earlier) and 2022 (and earlier) that could result in arbitrary code execution.
How severe is CVE-2023-21622?
CVE-2023-21622 has a severity rating of 7.8, which is considered high.
What software is affected by CVE-2023-21622?
FrameMaker 2020 Update 4 (and earlier) and 2022 (and earlier) are affected by CVE-2023-21622.
How can CVE-2023-21622 be exploited?
Exploitation of CVE-2023-21622 requires user interaction, specifically opening a malicious file.
Where can I find more information about CVE-2023-21622?
You can find more information about CVE-2023-21622 at the following link: [https://helpx.adobe.com/security/products/framemaker/apsb23-06.html](https://helpx.adobe.com/security/products/framemaker/apsb23-06.html)