CVE-2023-22235: Adobe InCopy SVG file Use After Free Arbitrary code execution
Published Apr 12, 2023
·Updated
InCopy versions 18.1 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe InCopy<17.4.1
Adobe InCopy>=18.0<18.2
macOS
Microsoft Windows
Event History
Apr 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe InCopy vulnerability?
The vulnerability ID for this Adobe InCopy vulnerability is CVE-2023-22235.
2
What is the severity of CVE-2023-22235?
The severity of CVE-2023-22235 is high (CVSS score: 7.8).
3
Which versions of InCopy are affected by CVE-2023-22235?
InCopy versions 18.1 and earlier, as well as 17.4 and earlier, are affected by CVE-2023-22235.
4
What is the impact of CVE-2023-22235?
CVE-2023-22235 could result in arbitrary code execution in the context of the current user.
5
How can CVE-2023-22235 be exploited?
Exploitation of CVE-2023-22235 requires user interaction, where a victim must open a malicious file.