Adobe InDesign Vulnerable to Integer Overflow or Wraparound Exploits

CVE-2024-41851
7.8HIGH

Key Information

Vendor
Adobe
Status
Indesign Desktop
Vendor
CVE Published:
14 August 2024

Summary

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Version(s)

InDesign Desktop <= 0

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.