CVE-2020-9727: Out-of-bounds memory access could lead to code execution
Published Sep 10, 2020
·Updated
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Affected Software
2 affected components
Adobe InDesign<=15.1.1
Apple macOS
Event History
Sep 10, 2020
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9727?
CVE-2020-9727 is rated as important due to the potential for code execution through memory corruption.
2
How do I fix CVE-2020-9727?
To fix CVE-2020-9727, update Adobe InDesign to version 15.1.2 or later.
3
What types of vulnerabilities are associated with CVE-2020-9727?
CVE-2020-9727 is associated with memory corruption vulnerabilities due to insecure handling of malicious files.
4
Is my version of Adobe InDesign affected by CVE-2020-9727?
Adobe InDesign versions 15.1.1 and earlier are affected by CVE-2020-9727.
5
What operating systems are impacted by CVE-2020-9727?
CVE-2020-9727 impacts Adobe InDesign on supported versions of Apple macOS.