Executive brief
Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the installation of malicious software in the context of the logged-in user.
Technical details
Adobe FrameMaker is vulnerable to a Type Confusion (CWE-843) flaw, officially categorized as 'Access of Resource Using Incompatible Type'. The vulnerability exists in versions 2022.8 and earlier. An attacker can exploit this by creating a malicious file that, when opened by a victim, causes the application to misinterpret data types in memory. This memory corruption can be leveraged to execute arbitrary code with the privileges of the current user. The attack requires local delivery of a file and user interaction (UI:R), but does not require prior authentication (PR:N).
Affected products
- Adobe FrameMaker 2022.8 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory