PT-2020-4585 · Adobe · Indesign

Published

2020-10-20

·

Updated

2021-12-10

·

CVE-2020-24421

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe InDesign versions 15.1.2 and earlier
Description The issue is related to handling malformed .indd files, which can cause a NULL pointer dereference bug, potentially leading to a denial-of-service of the client application. Additionally, it is described as a memory corruption vulnerability due to insecure handling of malicious .indd files, which could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this issue.
Recommendations For Adobe InDesign versions 15.1.2 and earlier, consider avoiding the use of malicious or malformed .indd files until a patch is available. As a temporary workaround, restrict the handling of .indd files to minimize the risk of exploitation.

Fix

Buffer Overflow

NULL Pointer Dereference

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05134
CVE-2020-24421

Affected Products

Indesign