Impact
Adobe Framemaker versions 2022.8 and earlier contain an Integer Underflow (Wrap or Wraparound) flaw that can be triggered when a malicious file is opened. The underflow is exploited during file parsing and gives the attacker the ability to execute arbitrary code as the current user. No additional privileges or remote access are required beyond the initial file opening, but the result is a full compromise of the user’s environment.
Affected Systems
Adobe Framemaker installed on a system with version 2022.8 or earlier is vulnerable. The issue arises in all product editions that include the vulnerable file parser component; no newer releases beyond 2022.8 are listed as affected.
Risk and Exploitability
The flaw carries a CVSS score of 7.8 indicating high severity. EPSS data is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires user interaction; a victim must open a specially crafted file. Once the file is opened, code execution occurs with the privileges of the logged‑in user. Consequently, the risk to systems that regularly process untrusted documents is significant, though the attack is localized to the user context.
OpenCVE Enrichment