PT-2023-7694 · Adobe · Indesign

Published

2023-12-12

·

Updated

2023-12-14

·

CVE-2023-47076

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Adobe InDesign versions 19.0 and earlier Adobe InDesign versions 17.4.2 and earlier
Description The issue is related to a NULL Pointer Dereference error in Adobe InDesign. Exploitation of this issue can allow an attacker to cause a denial-of-service by opening a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user, requiring user interaction to open a malicious file.
Recommendations For Adobe InDesign versions 19.0 and earlier, update to a version later than 19.0 to resolve the issue. For Adobe InDesign versions 17.4.2 and earlier, update to a version later than 17.4.2 to resolve the issue. As a temporary workaround, consider avoiding the opening of files from untrusted sources to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08761
CVE-2023-47076

Affected Products

Indesign