Impact
The vulnerability is a heap-based buffer overflow in Adobe InCopy, which can allow an attacker to run arbitrary code with the privileges of the current user. When a user opens a specially crafted malicious file, the overflow can be triggered, compromising confidentiality, integrity, and availability of the system. The weakness is identified as CWE-122.
Affected Systems
Adobe InCopy versions 21.3, 20.5.3, and all earlier releases are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV, suggesting no widespread exploitation yet. Exploitation requires user interaction: an attacker must deliver a malicious file and persuade a user to open it. Because this is a local file-based attack, no network access is needed.
OpenCVE Enrichment