Rapid7

vulnerability

Adobe FrameMaker: CVE-2022-28830: Out-of-bounds Read (CWE-125)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
May 13, 2022
Added
Feb 20, 2025
Modified
Mar 25, 2026

Description

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Solution

adobe-framemaker-fix-for-multiple-vulnerabilities-may-2022
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.