PT-2024-29599 · Adobe · Incopy
Published
2024-08-14
·
Updated
2024-10-15
·
CVE-2024-41858
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InCopy versions 19.4 and earlier
InCopy version 18.5.2
Description
The issue is an Integer Overflow or Wraparound that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, where a victim must open a malicious file.
Recommendations
For InCopy version 18.5.2, update to a version later than 18.5.2 to resolve the issue.
For InCopy versions prior to 19.4, update to a version later than 19.4 to resolve the issue.
As a temporary workaround, consider avoiding the opening of files from untrusted sources until a patch is available.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Incopy