CVE-2024-45137

InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which, when executed, could run arbitrary code in the context of the server. Exploitation of this issue requires user interaction.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-09 15:15

Updated : 2024-10-18 14:20


NVD link : CVE-2024-45137

Mitre link : CVE-2024-45137

CVE.ORG link : CVE-2024-45137


JSON object : View

Products Affected

adobe

  • indesign

apple

  • macos

microsoft

  • windows
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type