CVE-2024-41853
published 2024-08-14CVE-2024-41853: InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.36%
28.7th percentile
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | indesign | < 18.5.3 | 18.5.3 |
| adobe | indesign | >= 19.0 < 19.5 | 19.5 |
| adobe | indesign_desktop | <= ID18.5.2 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_oracle6.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwj3-xjmp-vq7m: InDesign Desktop versions ID19
ghsa_unreviewed·2024-08-14
CVE-2024-41853 [HIGH] CWE-122 GHSA-wwj3-xjmp-vq7m: InDesign Desktop versions ID19
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (HyperSQL Database) — CVE-2022-41853
vendor_oracle·2024-04-15·CVSS 6.7
CVE-2022-41853 [HIGH] Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (HyperSQL Database) — CVE-2022-41853
Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (HyperSQL Database) vulnerability
CVE: CVE-2022-41853
CVSS: 6.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2024 (APR 2024)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-14
Published