Adobe InDesign versions 13.0 and below have an exploitable Untrusted Search Path vulnerability. Successful exploitation could lead to local privilege escalation.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://helpx.adobe.com/security/products/indesign/apsb18-11.html | vendor advisory |
http://www.securityfocus.com/bid/103716 | third party advisory vdb entry |