CVE-2024-47423

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which can be automatically processed or executed by the system. Exploitation of this issue requires user interaction.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

18 Oct 2024, 14:15

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*
References () https://helpx.adobe.com/security/products/framemaker/apsb24-82.html - () https://helpx.adobe.com/security/products/framemaker/apsb24-82.html - Vendor Advisory
First Time Microsoft windows
Adobe framemaker
Adobe
Microsoft

09 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 15:15

Updated : 2024-10-18 14:15


NVD link : CVE-2024-47423

Mitre link : CVE-2024-47423


JSON object : View

Products Affected

adobe

  • framemaker

microsoft

  • windows
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type