Impact
Adobe Framemaker versions 2022.8 and earlier contain an integer underflow (wrap or wraparound) flaw that can be triggered by opening a malicious document, allowing an attacker to execute code in the context of the current user.
Affected Systems
Adobe Framemaker with revision 2022.8 or earlier is affected. The vulnerability applies to all users of the listed versions, regardless of operating system.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. The EPSS score is not available, so exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires the victim to open a specially crafted file, the attack vector is user interaction, and it can lead to arbitrary code execution if the user opens the malicious file.
OpenCVE Enrichment