Executive brief
Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security vulnerability that could lead to the exposure of sensitive information. An attacker could exploit this by tricking a user into opening a specially crafted malicious file. Successful exploitation could allow the attacker to access data stored in the computer's memory that they should not be able to see.
Technical details
An Access of Uninitialized Pointer vulnerability (CWE-824) exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw occurs when the application attempts to access a pointer that has not been properly initialized, potentially leading to the disclosure of sensitive memory contents. The attack vector is local, requiring a user to open a maliciously crafted file (User Interaction: Required). This vulnerability can result in a high impact on confidentiality but does not directly affect integrity or availability. Adobe has addressed this issue in newer versions of the software.
Affected products
- Adobe FrameMaker 2022.8 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory