Adobe Indesign XLS File Parsing Out Of Bound Write Remote Code execution vulnerability
CVE-2024-39391
7.8HIGH
Summary
InDesign Desktop, specifically versions ID19.4, ID18.5.2, and earlier, is vulnerable to an out-of-bounds write issue that can lead to arbitrary code execution within the context of the affected user's environment. Successful exploitation necessitates that the victim opens a specifically crafted malicious file. This vulnerability emphasizes the importance of verifying file origins and exercising caution when handling untrusted documents to mitigate potential risks. For comprehensive details on the vulnerability and remediation, refer to the official Adobe security advisory.
Affected Version(s)
InDesign Desktop 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre Database