Impact
A heap-based buffer overflow in Adobe Framemaker versions 2022.8 and earlier can cause memory contents to be exposed, allowing an attacker to read sensitive data stored in memory. This weakness is identified as CWE‑122 and does not provide a direct path to arbitrary code execution but can leak confidential information if exploited.
Affected Systems
Adobe Framemaker products released in 2022.8 or earlier are affected. All users of these versions should verify whether they have the vulnerable release.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate severity, and no EPSS value is available. It is not listed in the CISA KEV catalog. Exploitation requires user interaction; a victim must open a malicious file, suggesting the attack vector is typically local or remote via file sharing. Because of the need for user action, the immediate risk is lower compared to remote exploits, but uncontrolled disclosure of memory data remains a concern if the file is run.
OpenCVE Enrichment