CVE-2024-20766: Adobe Indesign 2024 TIF File Parsing Out-Of-Bound Read Information Disclosure Vulnerabiity
InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20766?
CVE-2024-20766 is considered a medium severity vulnerability due to the potential disclosure of sensitive memory.
How do I fix CVE-2024-20766?
To resolve CVE-2024-20766, update Adobe InDesign to version 18.5.2 or later.
What are the affected versions for CVE-2024-20766?
CVE-2024-20766 affects Adobe InDesign versions 18.5.1 and 19.2 and earlier.
Can CVE-2024-20766 be exploited remotely?
CVE-2024-20766 requires user interaction for exploitation, so it is not a remote vulnerability.
What types of systems are impacted by CVE-2024-20766?
CVE-2024-20766 impacts users of Adobe InDesign on both Windows and macOS systems.