CVE-2024-39394: Adobe Indesign 2024 PDF File Parsing Out Of Bound Write Remote Code Execution Vulnerability
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39394?
CVE-2024-39394 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-39394?
To resolve CVE-2024-39394, users should update Adobe InDesign to the latest version beyond 19.5 or 18.5.3.
What versions of Adobe InDesign are affected by CVE-2024-39394?
CVE-2024-39394 affects Adobe InDesign versions ID19.4, ID18.5.2, and earlier releases.
What can an attacker achieve by exploiting CVE-2024-39394?
Exploitation of CVE-2024-39394 may allow an attacker to execute arbitrary code on the victim's machine.
Does CVE-2024-39394 require user interaction for exploitation?
Yes, CVE-2024-39394 requires user interaction since a victim must open a malicious file.