PT-2020-4998 · Adobe · Indesign

Published

2020-09-08

·

Updated

2021-09-14

·

CVE-2020-9729

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions InDesign versions 15.1.1 and earlier
Description A memory corruption issue exists due to insecure handling of malicious indd files, potentially leading to out-of-bounds memory access and code execution in the context of the current user. This could be exploited by a remote attacker using a specially crafted file.
Recommendations For InDesign versions 15.1.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05583
CVE-2020-9729

Affected Products

Indesign