A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.
The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://helpx.adobe.com/security/products/indesign/apsb20-52.html | vendor advisory |