QID 376816

Date Published: 2022-08-10

QID 376816: Adobe FrameMaker Multiple Vulnerabilities (APSB22-42)

Adobe FrameMaker is a document processor designed for writing and editing large or complex documents, including structured documents.

CVE-2022-34264: Memory leak due to Out-of-bounds Read Vulnerability.
CVE-2022-35673: Arbitrary Code Execution due to Out-of-bounds Read Vulnerability.
CVE-2022-35674: Arbitrary Code Execution due to Out-of-bounds Read Vulnerability.
CVE-2022-35675: Arbitrary Code Execution due to Use After Free Vulnerability.
CVE-2022-35676: Arbitrary Code Execution due to Heap-based Buffer Overflow Vulnerability.
CVE-2022-35677: Arbitrary Code Execution due to Heap-based Buffer Overflow Vulnerability.
Affected Versions:
Adobe FrameMaker 2019 Release Update 8 and earlier
Adobe FrameMaker 2020 Release Update 4 and earlier. QID Detection Logic:(Authenticated)
This QID detects file versions of Adobe FrameMaker (FrameMaker.exe).

Successful exploitation of these vulnerabilities may allow an attacker to either execute arbitrary or memory leak of the target system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to update to latest available version of adobe framemaker. Please visit APSB22-27 for more details.
    Software Advisories
    Advisory ID Software Component Link
    APSB22-42 URL Logo helpx.adobe.com/security/products/framemaker/apsb22-42.html