Download the updated files applicable for your product's version.
Problem
Some security vulnerabilities that result in the following conditions have been identified in FrameMaker (2022 release) Update 7 and earlier, and FrameMaker (2020 release) Update 9 and earlier:
- Use-After-Free (UAF) vulnerabilities when parsing RTF files
- Out-of-bounds read vulnerability when parsing DOC files
For more information about these vulnerabilities, see Adobe Security Bulletin.
Solution
To resolve these issues, first close Adobe FrameMaker, then complete the following steps:
-
Extract the contents of the ZIP file. The ZIP contains the following updated files:
FrameMaker (2022 release)
- Sangam readers
- Reader for DOCX.smrd
- Reader for Excel.smrd
- Reader for RTF.smrd
- Reader for Word.smrd
- Reader for XLSX.smrd
- ImportUtility.dll
FrameMaker (2020 release)
- Sangam readers
- Reader for DOCX.smrd
- Reader for Excel.smrd
- Reader for RTF.smrd
- Reader for Word.smrd
- Reader for XLSX.smrd
- ImportUtility.dll
- Sangam readers
-
Navigate to the FrameMaker install location.
The default install location, depending on your version of FrameMaker, is:
FrameMaker (2020 release)
C:\Program Files\Adobe\Adobe FrameMaker 2020
FrameMaker (2022 release)
C:\Program Files\Adobe\Adobe FrameMaker 2022
-
Replace the existing files with the updated files you extracted in Step 2, at the following locations:
- ImportUtility.dll at <Install location>\filters
- Sangam readers at <Install location>\filters\Sangam\Readers
When prompted, click Yes to overwrite the existing files.
-
Launch FrameMaker.