PT-2020-4998 · Adobe · Indesign
Published
2020-09-08
·
Updated
2021-09-14
·
CVE-2020-9729
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
InDesign versions 15.1.1 and earlier
Description
A memory corruption issue exists due to insecure handling of malicious indd files, potentially leading to out-of-bounds memory access and code execution in the context of the current user. This could be exploited by a remote attacker using a specially crafted file.
Recommendations
For InDesign versions 15.1.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Memory Corruption
Access of Memory Location After End of Buffer
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indesign