Fix for stack-based buffer overflow vulnerability in Adobe FrameMaker

Problem

A stack-based buffer overflow vulnerability is identified in FrameMaker (2022 release) Update 5 and earlier, and FrameMaker (2020 release) Update 7 and earlier. The issue occurs while parsing malicious DOC files, that could lead to arbitrary code execution or system crashes.

For more information about this vulnerability, see Adobe Security Bulletin.

Solution

Perform the following steps to update the ImportUtility.dll file and resolve this issue:

  1. Download the updated ImportUtility.dll file applicable for your product's version.

  2. Extract the ZIP file to access the updated ImportUtility.dllfile.

  3. Navigate to the FrameMaker install location. The default paths are: 

    • FrameMaker (2022 release): C:\Program Files\Adobe\Adobe FrameMaker 2022\filters
    • FrameMaker (2020 release): C:\Program Files\Adobe\Adobe FrameMaker 2020\filters
  4. Replace the existing ImportUtility.dll file with the updated file. When prompted, select Yes to overwrite the existing file. 

  5. Launch FrameMaker.  

Get help faster and easier

New user?