CVE-2020-9729: Out-of-bounds memory access could lead to code execution
Published Sep 10, 2020
·Updated
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Affected Software
2 affected components
Adobe InDesign<=15.1.1
Apple macOS
Event History
Sep 10, 2020
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9729?
CVE-2020-9729 is considered a critical memory corruption vulnerability that could allow for code execution.
2
How do I fix CVE-2020-9729?
To mitigate CVE-2020-9729, update Adobe InDesign to version 15.1.2 or later.
3
Which versions of InDesign are affected by CVE-2020-9729?
CVE-2020-9729 affects Adobe InDesign versions up to and including 15.1.1.
4
What types of attacks could exploit CVE-2020-9729?
CVE-2020-9729 could be exploited through malicious indd files leading to out-of-bounds memory access.
5
Who is at risk from CVE-2020-9729?
Users of vulnerable versions of Adobe InDesign are at risk of potential code execution attacks.