Executive brief
Adobe FrameMaker, a professional document authoring and publishing solution, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands or software on the user's computer. This could lead to a full system compromise, data theft, or the installation of malware in the context of the affected user's account.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw occurs during the handling of malicious files, where the application writes data past the end of an intended buffer. An attacker can exploit this by convincing a victim to open a specially crafted file, leading to arbitrary code execution in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R). Adobe has addressed this in newer versions, and users are advised to update to version 2022.9 or later.
Affected products
- Adobe FrameMaker 2022.8 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory