Fix critical vulnerabilities in FrameMaker | August 2025

Problem

Some security vulnerabilities that result in the following conditions have been identified in FrameMaker (2022 release) Update 7 and earlier, and FrameMaker (2020 release) Update 9 and earlier:

  • Use-After-Free (UAF) vulnerabilities when parsing RTF files
  • Out-of-bounds read vulnerability when parsing DOC files

For more information about these vulnerabilities, see Adobe Security Bulletin.

 

Solution

To resolve these issues, first close Adobe FrameMaker, then complete the following steps:

  1. Download the updated files applicable for your product's version. 

  2. Extract the contents of the ZIP file. The ZIP contains the following updated files:  

    FrameMaker (2022 release)

    • Sangam readers
      • Reader for DOCX.smrd
      • Reader for Excel.smrd
      • Reader for RTF.smrd
      • Reader for Word.smrd
      • Reader for XLSX.smrd
    • ImportUtility.dll

    FrameMaker (2020 release)

    • Sangam readers
      • Reader for DOCX.smrd
      • Reader for Excel.smrd
      • Reader for RTF.smrd
      • Reader for Word.smrd
      • Reader for XLSX.smrd
    • ImportUtility.dll
  3. Navigate to the FrameMaker install location.

    The default install location, depending on your version of FrameMaker, is:

    FrameMaker (2020 release)

    C:\Program Files\Adobe\Adobe FrameMaker 2020

    FrameMaker (2022 release)

    C:\Program Files\Adobe\Adobe FrameMaker 2022

  4. Replace the existing files with the updated files you extracted in Step 2, at the following locations:

    • ImportUtility.dll at <Install location>\filters
    • Sangam readers at <Install location>\filters\Sangam\Readers

    When prompted, click Yes to overwrite the existing files. 

  5. Launch FrameMaker.  

Adobe, Inc.

Get help faster and easier

New user?