helpx.adobe.comVendor advisory
https://helpx.adobe.com/security/products/incopy/apsb24-79.html CVE-2024-45137
HIGH
InDesign Desktop | Unrestricted Upload of File with Dangerous Type (CWE-434)
Record summary
CVE-2024-45137 has a selected CVSS score of 7.8 (high).
Description
InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which, when executed, could run arbitrary code in the context of the server. Exploitation of this issue requires user interaction.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
InDesign DesktopBrowse Adobe / InDesign DesktopDefault status: affected | CVE List | Through 18.5.3 | affected |
indesignBrowse adobe / indesignDefault status: unknown | CVE List | Through 18.5.3 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45137