CVE-2024-41866: Adobe Indesign 2024 DOC File Parsing Null Pointer Dereference
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41866?
CVE-2024-41866 has a severity rating that indicates it can lead to a denial-of-service (DoS) condition.
How do I fix CVE-2024-41866?
To mitigate CVE-2024-41866, users should update Adobe InDesign to the latest version available.
What versions of InDesign are affected by CVE-2024-41866?
CVE-2024-41866 affects InDesign Desktop versions ID19.4, ID18.5.2 and earlier.
Can CVE-2024-41866 be exploited remotely?
CVE-2024-41866 requires interaction with the vulnerable InDesign application, making it less likely to be exploited remotely.
What type of vulnerability is CVE-2024-41866?
CVE-2024-41866 is classified as a NULL Pointer Dereference vulnerability.