QID 376726
Date Published: 2022-07-13
QID 376726: Adobe RoboHelp Server Arbitrary code execution Vulnerability (ASPB22-10)
Adobe RoboHelp Server extends the capabilities of Adobe RoboHelp and Adobe FrameMaker. Merge multiple segments of Help content, including responsive HTML5 content, into a unified information system. Host it for anytime, anywhere, any device access.
Affected Versions:
Adobe RoboHelp Server RH2020.0.7 and earlier versions
QID Detection Logic:(Authenticated)
This QID checks for vulnerable version ofAdobe RoboHelp Server by checking the file version of "AfterFX.exe".
Successful exploitation could lead to arbitrary code execution in the context of the current user.
Solution
The vendor has released an update to fix the vulnerability. Please refer to Adobe advisory APSB22-10 for more details.
Vendor References
CVEs related to QID 376726
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| https://helpx.adobe.com/security/products/robohelp/apsb22-10.html |
|