CVE-2020-9730: Out-of-bounds memory access could lead to code execution
Published Sep 10, 2020
·Updated
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Affected Software
2 affected components
Adobe InDesign<=15.1.1
Apple macOS
Event History
Sep 10, 2020
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9730?
CVE-2020-9730 is classified as a critical memory corruption vulnerability.
2
How do I fix CVE-2020-9730?
To fix CVE-2020-9730, update Adobe InDesign to version 15.1.2 or later.
3
What versions of InDesign are affected by CVE-2020-9730?
InDesign versions 15.1.1 and earlier are affected by CVE-2020-9730.
4
Can CVE-2020-9730 lead to code execution?
Yes, CVE-2020-9730 can potentially lead to arbitrary code execution in the context of the current user.
5
Is the macOS operating system affected by CVE-2020-9730?
No, macOS itself is not vulnerable to CVE-2020-9730, but the Adobe InDesign application running on it is.