CVE-2024-49508: InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49508?
CVE-2024-49508 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-49508?
To fix CVE-2024-49508, update Adobe InDesign to the latest version that is beyond 18.5.3 or 19.x if applicable.
Who is affected by CVE-2024-49508?
CVE-2024-49508 affects Adobe InDesign Desktop versions ID18.5.2, ID19.5 and earlier.
What can attackers do with CVE-2024-49508?
Attackers can exploit CVE-2024-49508 to execute arbitrary code in the context of the current user if the vulnerable version is opened.
Is user interaction required to exploit CVE-2024-49508?
Yes, exploitation of CVE-2024-49508 requires user interaction, such as opening a malicious file.