First published: Thu Sep 10 2020(Updated: )
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe InDesign | <=15.1.1 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9731 is a memory corruption vulnerability in Adobe InDesign 15.1.1 and earlier versions.
CVE-2020-9731 affects Adobe InDesign 15.1.1 and earlier versions by insecure handling of a malicious indd file.
The severity of CVE-2020-9731 is high (7.8).
CVE-2020-9731 can be exploited by abusing the insecure handling of a malicious indd file to cause an out-of-bounds memory access and potentially execute code in the current user's context.
To fix CVE-2020-9731, update Adobe InDesign to version 15.1.2 or later as recommended by the vendor.