First published: Wed Oct 09 2024(Updated: )
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application could unknowingly execute. This could allow the attacker to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe FrameMaker | <2020.7 | |
Adobe FrameMaker | >=2022<2022.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-47422 is critical due to the potential for arbitrary code execution.
To fix CVE-2024-47422, users should update Adobe Framemaker to version 2020.7 or higher, or 2022.5 or higher.
CVE-2024-47422 affects Adobe Framemaker versions 2020.6, 2022.4, and earlier.
CVE-2024-47422 is classified as an Untrusted Search Path vulnerability.
An attacker exploiting CVE-2024-47422 could potentially execute arbitrary code on the affected system.