helpx.adobe.comVendor advisory
https://helpx.adobe.com/security/products/framemaker/apsb24-82.html CVE-2024-47423
HIGH
Adobe Framemaker | Unrestricted Upload of File with Dangerous Type (CWE-434)
Record summary
CVE-2024-47423 has a selected CVSS score of 7.8 (high).
Description
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which can be automatically processed or executed by the system. Exploitation of this issue requires user interaction.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Adobe FramemakerBrowse Adobe / Adobe FramemakerDefault status: affected | CVE List | Through 2022.4 | affected |
framemakerBrowse adobe / framemakerDefault status: unknown | CVE List | Through 2022.4 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-47423