Impact
Adobe Framemaker contains a use‑after‑free flaw (CWE‑416) that enables an attacker to execute arbitrary code when a malicious file is opened by a user. The vulnerability is triggered by crafted input, and execution occurs with the privileges of the current user, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
Adobe Framemaker versions 2022.8 and earlier are affected. The flaw impacts all operating systems supported by those releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, yet exploitation requires user interaction, limiting the attack vector to social engineering of file opening. EPSS is not available, and the vulnerability is not listed in KEV, but the potential for privilege escalation makes it a significant concern for environments where users routinely open Framemaker documents.
OpenCVE Enrichment