First published: Tue Nov 16 2021(Updated: )
Adobe InDesign versions 16.4 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Adobe InDesign 2025 | <=16.4 | |
Any of | ||
macOS | ||
Microsoft Windows Operating System | ||
Adobe InDesign 2025 | <=16.4 | |
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42731 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2021-42731, update Adobe InDesign to the latest version beyond 16.4.
CVE-2021-42731 affects users of Adobe InDesign versions 16.4 and earlier.
CVE-2021-42731 is associated with a buffer overflow attack that can lead to arbitrary code execution.
Yes, exploitation of CVE-2021-42731 can potentially allow an attacker to execute arbitrary code in the context of the current user.