---
cve: "CVE-2024-30300"
severity: "CRITICAL"
cvss: 9.8
epss: "73%"
vendor: "Adobe"
kev: false
exploited: false
published: "2024-06-13 12:15:10"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-04T07:03:15+02:00"
---

# CVE-2024-30300

> 9.8 CRITICAL

## Beschreibung

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include system or user privileges. Exploitation of this issue does not require user interaction.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-200** — Exposure of Sensitive Information to an Unauthorized Actor
  The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

## Angriffsmuster (CAPEC)

- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-22 — Exploiting Trust in Client](https://capec.mitre.org/data/definitions/22.html) _(Severity: High)_
- [CAPEC-116 — Excavation](https://capec.mitre.org/data/definitions/116.html) _(Severity: Medium)_
- [CAPEC-169 — Footprinting](https://capec.mitre.org/data/definitions/169.html) _(Severity: Very Low)_
- [CAPEC-224 — Fingerprinting](https://capec.mitre.org/data/definitions/224.html) _(Severity: Very Low)_
- [CAPEC-285 — ICMP Echo Request Ping](https://capec.mitre.org/data/definitions/285.html) _(Severity: Low)_
- [CAPEC-287 — TCP SYN Scan](https://capec.mitre.org/data/definitions/287.html) _(Severity: Low)_
- [CAPEC-290 — Enumerate Mail Exchange (MX) Records](https://capec.mitre.org/data/definitions/290.html) _(Severity: Low)_

## ATT&CK-Techniken

- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)
- [T1217 — Browser Bookmark Discovery](https://attack.mitre.org/techniques/T1217/)
- [T1592 — Gather Victim Host Information](https://attack.mitre.org/techniques/T1592/)
- [T1595 — Active Scanning](https://attack.mitre.org/techniques/T1595/)

## Referenzen

- <https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-38.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-30300) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
