CVE-2019-7107

CRITICAL

Adobe InDesign < 14.0.1 - Remote Code Execution via Hyperlink Processing

Title source: llm
STIX 2.1

Description

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://helpx.adobe.com/security/products/indesign/apsb19-23.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107821

Scores

CVSS v3 9.8
EPSS 0.2781
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
adobe/indesign < 14.0.1
Published May 23, 2019
Tracked Since Feb 18, 2026