CVE-2018-15974 describes an insecure library loading (DLL hijacking) vulnerability in Adobe FrameMaker versions 1.0.5.1 and earlier. This vulnerability has a CVSS score of 7.8 (High), indicating that an attacker could achieve privilege escalation through a low-complexity attack, requiring user interaction, to gain high confidentiality, integrity, and availability impact. While there is no known active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.361CPE matchmatch criteria | cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.