First published: Tue Dec 10 2024(Updated: )
InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe InDesign 2025 | <=18.5.4 | |
Adobe InDesign 2025 | >=19.0<19.5.1 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49548 has been rated as a critical vulnerability due to its potential to disclose sensitive memory information.
To remediate CVE-2024-49548, users should update to the latest version of Adobe InDesign that is not affected by this vulnerability.
CVE-2024-49548 affects Adobe InDesign versions ID19.5, ID18.5.4, and earlier.
CVE-2024-49548 requires user interaction for exploitation, which limits the scope of a remote attack.
CVE-2024-49548 specifically affects Adobe InDesign and does not impact the operating systems themselves, including Apple macOS or Microsoft Windows.