First published: Thu Jan 13 2022(Updated: )
Adobe InDesign version 16.4 (and earlier) is affected by a use-after-free vulnerability in the processing of a JPEG2000 file that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe InDesign | <=16.4 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe InDesign vulnerability is CVE-2021-45059.
The severity level of CVE-2021-45059 is medium (3.3).
The affected software for CVE-2021-45059 is Adobe InDesign version 16.4 (and earlier).
CVE-2021-45059 could lead to disclosure of sensitive memory and bypassing of mitigations such as ASLR.
Yes, Adobe has released a security update to address the vulnerability. Please refer to the Adobe security bulletin APSB22-05 for more information.