CVE-2024-49548: InDesign Desktop | Out-of-bounds Read (CWE-125)
InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49548?
CVE-2024-49548 has been rated as a critical vulnerability due to its potential to disclose sensitive memory information.
How do I fix CVE-2024-49548?
To remediate CVE-2024-49548, users should update to the latest version of Adobe InDesign that is not affected by this vulnerability.
What versions of InDesign are affected by CVE-2024-49548?
CVE-2024-49548 affects Adobe InDesign versions ID19.5, ID18.5.4, and earlier.
Can CVE-2024-49548 be exploited remotely?
CVE-2024-49548 requires user interaction for exploitation, which limits the scope of a remote attack.
Does CVE-2024-49548 impact Apple macOS or Microsoft Windows?
CVE-2024-49548 specifically affects Adobe InDesign and does not impact the operating systems themselves, including Apple macOS or Microsoft Windows.