CVE-2020-24421: Adobe InDesign 15.1.2 NULL Pointer Dereference Bug
Published Oct 21, 2020
·Updated
Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue.
Affected Software
2 affected components
Adobe InDesign<=15.1.2
Microsoft Windows
Event History
Oct 20, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-24421?
CVE-2020-24421 has a severity rating that indicates a denial-of-service vulnerability in Adobe InDesign.
2
How do I fix CVE-2020-24421?
To fix CVE-2020-24421, upgrade your Adobe InDesign to version 15.1.3 or later.
3
What versions of Adobe InDesign are affected by CVE-2020-24421?
Adobe InDesign versions 15.1.2 and earlier are affected by CVE-2020-24421.
4
What type of attack is associated with CVE-2020-24421?
CVE-2020-24421 is associated with a denial-of-service attack that requires user interaction.
5
Is user interaction necessary to exploit CVE-2020-24421?
Yes, user interaction is required to exploit CVE-2020-24421 by opening a malformed .indd file.