PT-2020-5000 · Adobe · Indesign

Published

2020-09-08

·

Updated

2021-09-14

·

CVE-2020-9731

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe InDesign versions 15.1.1 and earlier
Description A memory corruption issue exists due to insecure handling of malicious indd files, potentially leading to out-of-bounds memory access and code execution in the context of the current user. This could be exploited by a remote attacker using a specially crafted file.
Recommendations For Adobe InDesign versions 15.1.1 and earlier, update to a version that fixes this issue to prevent potential code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05585
CVE-2020-9731

Affected Products

Indesign