Unrestricted File Upload Vulnerability in Adobe InDesign Desktop
CVE-2024-45137
7.8HIGH
Summary
Adobe InDesign Desktop is affected by a vulnerability that allows an unrestricted upload of files with dangerous types, potentially leading to arbitrary code execution on the server where the application is running. Attackers can exploit this flaw by tricking users into uploading malicious files that, when executed, may run arbitrary code in the server's context. This exploit requires user interaction, heightening the importance of user awareness and security measures to mitigate potential risks. Users of affected versions are encouraged to follow security guidelines as outlined by Adobe to enhance their protection against such vulnerabilities.
References
EPSS Score
2% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database