CVE-2024-39390: Adobe Indesign 2024 DOC File Parsing Memory Corruption
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39390?
CVE-2024-39390 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-39390?
To mitigate CVE-2024-39390, users should update Adobe InDesign to the latest version available.
What versions of Adobe InDesign are affected by CVE-2024-39390?
CVE-2024-39390 affects Adobe InDesign versions ID19.4, ID18.5.2, and earlier.
Is exploitation of CVE-2024-39390 possible without user interaction?
No, exploitation of CVE-2024-39390 requires user interaction, as a malicious file must be opened by the victim.
What are the risks associated with CVE-2024-39390?
The risks associated with CVE-2024-39390 include the potential for attackers to execute arbitrary code on the user's machine.