Executive brief
Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security flaw that allows unauthorized access to local files. An attacker could trick a user into opening a specially crafted document, which then allows the attacker to read sensitive information from the victim's computer. This could lead to the theft of private data or corporate intellectual property stored on the affected system.
Technical details
An improper input validation vulnerability (CWE-20) exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw occurs when the application fails to properly validate input within a document file, which can be exploited to perform an arbitrary file system read. The attack vector is local, requiring a victim to manually open a maliciously crafted file provided by the attacker. Successful exploitation allows the attacker to bypass security boundaries and read sensitive files from the local file system with the permissions of the current user. Adobe has addressed this issue in version 2022.9.
Affected products
- Adobe FrameMaker 2022.8 and earlier
Timeline
- 2026-04-14: advisory: Initial disclosure by Adobe and NVD publication
- 2026-04-14: patched: Adobe released version 2022.9 to address the issue