Adobe Framemaker versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://helpx.adobe.com/security/products/framemaker/apsb18-37.html | patch vendor advisory |
http://www.securityfocus.com/bid/105537 | third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/151002 | vdb entry third party advisory |