First published: Tue Oct 20 2020(Updated: )
Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe InDesign | <=15.1.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24421 has a severity rating that indicates a denial-of-service vulnerability in Adobe InDesign.
To fix CVE-2020-24421, upgrade your Adobe InDesign to version 15.1.3 or later.
Adobe InDesign versions 15.1.2 and earlier are affected by CVE-2020-24421.
CVE-2020-24421 is associated with a denial-of-service attack that requires user interaction.
Yes, user interaction is required to exploit CVE-2020-24421 by opening a malformed .indd file.