QID 377888

Date Published: 2023-01-11

QID 377888: Adobe InCopy Arbitrary Code Execution Vulnerability (APSB23-08)

Adobe InCopy is a professional word processor developed and marketed by Adobe Systems.

Affected Versions:
Adobe InCopy - ID18.0 and earlier version Windows and MacOS
Adobe InCopy - ID17.4 and earlier version Windows and MacOS

QID Detection Logic:(Authenticated)
This QID checks vulnerable versions of Adobe InCopy.

Successful exploitation could lead to arbitrary code execution and memory leak.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 3.8 severity.
  • Solution

    Adobe has released fix to address this issue. Customers are advised to refer to APSB23-08 for updates pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    APSB23-08 URL Logo helpx.adobe.com/security/products/incopy/apsb23-08.html