Executive brief
The license server component for Adobe FrameMaker contains a security flaw that allows a person with local access to the computer to overwrite system files. This could lead to a complete takeover of the machine, including gaining administrative (root) privileges. Such an exploit could result in unauthorized data access or permanent damage to the operating system.
Technical details
The Adobe FrameMaker fm_fls license server contains a vulnerability that allows local users to overwrite arbitrary files on the system. This is likely due to insecure file handling or temporary file creation with elevated privileges. By targeting critical system files, a local attacker can escalate their privileges to root. The vulnerability requires local access to the host machine but no specific user authentication within the application. While the CVSS 2.0 score is low (2.1), the impact includes potential full system compromise.
Affected products
- Adobe FrameMaker fm_fls license server
Timeline
- 1996-08-14: disclosed