First published: Tue Dec 10 2024(Updated: )
InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe InDesign 2025 | <=18.5.4 | |
Adobe InDesign 2025 | >=19.0<19.5.1 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49549 has a high severity rating due to its potential for sensitive data disclosure through an out-of-bounds read.
To fix CVE-2024-49549, users should update Adobe InDesign to the latest version available.
CVE-2024-49549 affects Adobe InDesign versions 19.5, 18.5.4, and earlier versions.
Exploitation of CVE-2024-49549 may allow attackers to access sensitive memory, bypassing security mitigations like ASLR.
Exploitation of CVE-2024-49549 generally requires user interaction to execute malicious content in InDesign.