Junglewise Threat Intelligence

CVE-2026-27300: Adobe FrameMaker uninitialized pointer access memory disclosure

CVE-2026-27300 · Severity: medium · CVSS 5.5 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security vulnerability that could lead to the exposure of sensitive information. An attacker could exploit this by tricking a user into opening a specially crafted malicious file. Successful exploitation could allow the attacker to access data stored in the computer's memory that they should not be able to see.

Technical details

An Access of Uninitialized Pointer vulnerability (CWE-824) exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw occurs when the application attempts to access a pointer that has not been properly initialized, potentially leading to the disclosure of sensitive memory contents. The attack vector is local, requiring a user to open a maliciously crafted file (User Interaction: Required). This vulnerability can result in a high impact on confidentiality but does not directly affect integrity or availability. Adobe has addressed this issue in newer versions of the software.

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats