helpx.adobe.comVendor advisory
https://helpx.adobe.com/security/products/incopy/apsb24-79.html CVE-2024-45136
HIGH
InCopy | Unrestricted Upload of File with Dangerous Type (CWE-434)
Record summary
CVE-2024-45136 has a selected CVSS score of 7.8 (high).
Description
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
InCopyBrowse Adobe / InCopyDefault status: affected | CVE List | Through 18.5.3 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45136