QID 376726

Date Published: 2022-07-13

QID 376726: Adobe RoboHelp Server Arbitrary code execution Vulnerability (ASPB22-10)

Adobe RoboHelp Server extends the capabilities of Adobe RoboHelp and Adobe FrameMaker. Merge multiple segments of Help content, including responsive HTML5 content, into a unified information system. Host it for anytime, anywhere, any device access.

Affected Versions:
Adobe RoboHelp Server RH2020.0.7 and earlier versions

QID Detection Logic:(Authenticated)
This QID checks for vulnerable version ofAdobe RoboHelp Server by checking the file version of "AfterFX.exe".

Successful exploitation could lead to arbitrary code execution in the context of the current user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has released an update to fix the vulnerability. Please refer to Adobe advisory APSB22-10 for more details.

    CVEs related to QID 376726

    Software Advisories
    Advisory ID Software Component Link
    https://helpx.adobe.com/security/products/robohelp/apsb22-10.html URL Logo helpx.adobe.com/security/products/robohelp/apsb22-10.html