ZDI-23-074: Adobe InCopy Font Parsing Use-After-Free Information Disclosure Vulnerability
Published Jan 18, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe InCopy. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Adobe InCopy
Event History
Jan 18, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-074?
The severity of ZDI-23-074 is classified as moderate.
2
How do I fix ZDI-23-074?
To fix ZDI-23-074, update Adobe InCopy to the latest version provided by Adobe.
3
What type of attacks can exploit ZDI-23-074?
ZDI-23-074 can be exploited by remote attackers through user interaction, requiring users to visit a malicious page or open a malicious file.
4
What information can be disclosed due to ZDI-23-074?
ZDI-23-074 may lead to the disclosure of sensitive information on affected installations of Adobe InCopy.
5
Who is affected by ZDI-23-074?
Users and installations of Adobe InCopy are affected by the ZDI-23-074 vulnerability.