CVE-2018-15974Untrusted Search Path in Adobe Framemaker

Severity
7.8HIGHNVD
EPSS
1.9%
top 16.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 14

Description

Adobe Framemaker versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDadobe/framemaker14.0.361
CVEListV5adobe/adobe_framemaker1.0.5.1 and below versions

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gjqm-xj5v-7cvf: Adobe Framemaker versions 12022-05-14
CVEList
CVE-2018-15974: Adobe Framemaker versions 12018-10-17
CVE-2018-15974 — Untrusted Search Path in Adobe | cvebase