Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-45137


InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which, when executed, could run arbitrary code in the context of the server. Exploitation of this issue requires user interaction.


Published

2024-10-09T15:15:13.373

Last Modified

2024-10-18T14:20:27.983

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe indesign < 18.5.4 Yes
Application adobe indesign < 19.5 Yes
Operating System apple macos - No
Operating System microsoft windows - No

References