CVE-2024-39395: Adobe Indesign 2024 DOC File Parsing Null Pointer Dereference
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a DoS condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39395?
CVE-2024-39395 has been rated as a medium severity vulnerability due to its potential to cause application denial-of-service.
How do I fix CVE-2024-39395?
To mitigate CVE-2024-39395, ensure that you update Adobe InDesign to version 19.5 or later.
Which versions of Adobe InDesign are affected by CVE-2024-39395?
CVE-2024-39395 affects Adobe InDesign versions ID19.4, ID18.5.2, and earlier versions.
What type of vulnerability is CVE-2024-39395?
CVE-2024-39395 is a NULL Pointer Dereference vulnerability that can lead to application crashes.
Can CVE-2024-39395 be exploited remotely?
Yes, CVE-2024-39395 can potentially be exploited by an attacker to crash the application, resulting in a denial-of-service.