InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple macos Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Apple
Apple macos Microsoft Microsoft windows |
Wed, 09 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe incopy |
|
CPEs | cpe:2.3:a:adobe:incopy:-:*:*:*:*:*:*:* | |
Vendors & Products |
Adobe
Adobe incopy |
|
Metrics |
ssvc
|
Wed, 09 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction. | |
Title | InCopy | Unrestricted Upload of File with Dangerous Type (CWE-434) | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2024-10-09T14:05:03.366Z
Updated: 2024-10-09T14:37:20.156Z
Reserved: 2024-08-21T23:00:59.349Z
Link: CVE-2024-45136
Vulnrichment
Updated: 2024-10-09T14:37:15.519Z
NVD
Status : Analyzed
Published: 2024-10-09T15:15:13.163
Modified: 2024-10-18T14:20:49.137
Link: CVE-2024-45136
Redhat
No data.