Lucene search

K
cvelistAdobeCVELIST:CVE-2020-9731
HistorySep 10, 2020 - 6:29 p.m.

CVE-2020-9731 Out-of-bounds memory access could lead to code execution

2020-09-1018:29:05
CWE-788
adobe
www.cve.org
8
cve-2020-9731
out-of-bounds memory access
code execution
insecure handling
malicious indd file

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.9%

A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

CNA Affected

[
  {
    "product": "InDesign",
    "vendor": "Adobe",
    "versions": [
      {
        "lessThanOrEqual": "15.1.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "None",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.9%

Related for CVELIST:CVE-2020-9731