CVE-2021-21056
Adobe Framemaker version 2020.0.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Framemaker version 2020.0.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 21.22% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- adobe/framemaker
- Source
- psirt@adobe.com
References
- https://helpx.adobe.com/security/products/framemaker/apsb21-14.htmlPatch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-282/Third Party Advisory
- https://helpx.adobe.com/security/products/framemaker/apsb21-14.htmlPatch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-282/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.