CVE-2020-9728: Out-of-bounds memory access could lead to code execution
Published Sep 10, 2020
·Updated
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Affected Software
2 affected components
Adobe InDesign<=15.1.1
Apple macOS
Event History
Sep 10, 2020
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9728?
CVE-2020-9728 is rated as critical due to its potential for code execution through memory corruption.
2
How do I fix CVE-2020-9728?
To fix CVE-2020-9728, update Adobe InDesign to version 15.1.2 or later.
3
What versions of InDesign are affected by CVE-2020-9728?
Only Adobe InDesign versions up to and including 15.1.1 are affected by CVE-2020-9728.
4
What type of vulnerability is CVE-2020-9728?
CVE-2020-9728 is a memory corruption vulnerability that can lead to out-of-bounds memory access.
5
What can an attacker achieve with CVE-2020-9728?
An attacker can exploit CVE-2020-9728 to execute arbitrary code in the context of the current user.