CVE-2022-30676: Adobe InDesign 2022 Out-of-Bound Read Memory leak
Published Sep 16, 2022
·Updated
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe InDesign>=16.0<=16.4.2
Adobe InDesign>=17.0<=17.3
Apple macOS
Microsoft Windows
Event History
Sep 16, 2022
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Adobe InDesign vulnerability?
The vulnerability ID is CVE-2022-30676.
2
What is the severity rating of CVE-2022-30676?
The severity rating is 5.5 (medium).
3
Which versions of Adobe InDesign are affected by CVE-2022-30676?
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected.
4
What is the impact of CVE-2022-30676?
The vulnerability could lead to the disclosure of sensitive memory and bypassing of mitigations such as ASLR.
5
Is Apple macOS or Microsoft Windows affected by CVE-2022-30676?
No, Apple macOS and Microsoft Windows are not vulnerable to this vulnerability.