CVE-2022-38414: Adobe InDesign SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38414?
CVE-2022-38414 is a Heap-based Buffer Overflow vulnerability in Adobe InDesign that could allow arbitrary code execution.
Which versions of Adobe InDesign are affected by CVE-2022-38414?
Adobe InDesign versions 16.4.2 and earlier, as well as version 17.3 and earlier, are affected by CVE-2022-38414.
How does CVE-2022-38414 impact the user?
Exploitation of CVE-2022-38414 requires user interaction, where a victim must open a malicious file, and it could result in arbitrary code execution.
Is Apple macOS affected by CVE-2022-38414?
No, Apple macOS is not vulnerable to CVE-2022-38414.
Is Microsoft Windows affected by CVE-2022-38414?
No, Microsoft Windows is not vulnerable to CVE-2022-38414.
How can I learn more about CVE-2022-38414?
You can find more information about CVE-2022-38414 on the Adobe Security Bulletin APSB22-50: [link](https://helpx.adobe.com/security/products/indesign/apsb22-50.html).