CVE-2020-9731: Out-of-bounds memory access could lead to code execution
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9731?
CVE-2020-9731 is a memory corruption vulnerability in Adobe InDesign 15.1.1 and earlier versions.
How does CVE-2020-9731 affect Adobe InDesign?
CVE-2020-9731 affects Adobe InDesign 15.1.1 and earlier versions by insecure handling of a malicious indd file.
What is the severity of CVE-2020-9731?
The severity of CVE-2020-9731 is high (7.8).
How can CVE-2020-9731 be exploited?
CVE-2020-9731 can be exploited by abusing the insecure handling of a malicious indd file to cause an out-of-bounds memory access and potentially execute code in the current user's context.
How can I fix CVE-2020-9731?
To fix CVE-2020-9731, update Adobe InDesign to version 15.1.2 or later as recommended by the vendor.