PT-2020-4999 · Adobe · Indesign

Published

2020-09-08

·

Updated

2021-09-14

·

CVE-2020-9730

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions InDesign versions 15.1.1 and earlier
Description A memory corruption issue exists due to insecure handling of malicious indd files, potentially leading to out-of-bounds memory access and code execution in the context of the current user. This could be exploited by a remote attacker using a specially crafted file.
Recommendations For InDesign versions 15.1.1 and earlier, update to a version that fixes this issue to prevent potential code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05584
CVE-2020-9730

Affected Products

Indesign