QID 375617

Date Published: 2021-06-09

QID 375617: Adobe RoboHelp Server Arbitrary code execution Vulnerability (ASPB21-44)

Adobe RoboHelp Server extends the capabilities of Adobe RoboHelp and Adobe FrameMaker. Merge multiple segments of Help content, including responsive HTML5 content, into a unified information system. Host it for anytime, anywhere, any device access.

Affected Versions:
Adobe RoboHelp Server 2019.0.9 and earlier versions

QID Detection Logic:(Authenticated)
This QID checks for vulnerable version ofAdobe RoboHelp Server by checking the file version of "AfterFX.exe".

Successful exploitation could lead to arbitrary code execution in the context of the current user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released an update to fix the vulnerability. Please refer to Adobe advisory APSB21-44 for more details.

    CVEs related to QID 375617

    Software Advisories
    Advisory ID Software Component Link
    ASPB21-44 URL Logo helpx.adobe.com/security/products/robohelp-server/apsb21-44.html