CVE-2021-28596 is an out-of-bounds write vulnerability affecting Adobe FrameMaker versions 2020.0.1 and earlier, and 2019.0.8 and earlier. This vulnerability carries a CVSS score of 7.8 (High), indicating that an unauthenticated attacker could achieve arbitrary code execution by tricking a user into opening a specially crafted malicious file. While user interaction is required for exploitation, successful attacks could lead to full compromise of the affected system. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code, and community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019.0.8CPE match | cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* | ||
<= 2020.0.1CPE match | cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* | ||
2020.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:framemaker:2020.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.