Adobe InDesign Font Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published Sep 11, 2023
7.8
HIGHCVSS 3.1
EPSS 0.45%
Description
Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected products
-
Affected
- ≥ 0, ≤ 17.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Adobe | InDesign Desktop | affected | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-33269 Advisory
- https://helpx.adobe.com/security/products/indesign/apsb22-23.html vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-33269 | Advisory | |
| https://helpx.adobe.com/security/products/indesign/apsb22-23.html | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data