CVE-2024-47422 is an Untrusted Search Path vulnerability affecting Adobe Framemaker versions 2020.6, 2022.4, and earlier, which could lead to arbitrary code execution. This high-severity vulnerability (CVSS 7.8) requires user interaction, where an attacker could trick a user into executing malicious code by inserting a malicious path into the application's search directories. While the potential impact is significant (confidentiality, integrity, and availability), there is currently no evidence of active exploitation, public exploit code, or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.7CPE matchmatch criteria | cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* | ||
>= 2022, < 2022.5CPE matchmatch criteria | cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.