PT-2024-10271 · Adobe · Framemaker

Published

2024-12-10

·

Updated

2024-12-13

·

CVE-2024-53959

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Framemaker versions 2020.7, 2022.5 and earlier
Description The issue is a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. To exploit this problem, user interaction is necessary, as the victim must open a malicious file. This allows an attacker to potentially execute arbitrary code in the context of the current user using a specially crafted file.
Recommendations For versions 2020.7 and earlier, update to a version later than 2022.5 to resolve the issue. For version 2022.5, consider avoiding the use of potentially malicious files until a patch is available. As a temporary workaround, consider restricting the ability to open files from untrusted sources to minimize the risk of exploitation.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-00677
CVE-2024-53959

Affected Products

Framemaker