Vulnerabilities > CVE-2019-7107 - Unspecified vulnerability in Adobe Indesign

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
adobe
critical
nessus

Summary

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

Nessus

  • NASL familyWindows
    NASL idADOBE_INDESIGN_APSB19-23.NASL
    descriptionThe version of Adobe InDesign installed on the remote Windows host is prior to 13.1.1, or 14.x prior to 14.0.2. It is, therefore, affected by an Arbitrary Code Execution vulnerability due to unsafe hyperlink processing in the Webkit component of MacOS. An authenticated, remote attacker can exploit this issue to cause execution of arbitary code or the application to stop responding.
    last seen2020-06-01
    modified2020-06-02
    plugin id124022
    published2019-04-12
    reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/124022
    titleAdobe InDesign < 13.1.1 / 14.x < 14.0.2 Arbitrary Code Execution Vulnerability (APSB19-23)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_ADOBE_INDESIGN_APSB19-23.NASL
    descriptionThe version of Adobe InDesign installed on the remote macOS or Mac OS X host is prior to 14.0.2. It is, therefore, affected by a Arbitrary Code Execution vulnerability exists due to unsafe hyperlink processing vulnerability exists Webkit component of MacOS. An authenticated, remote attacker can exploit this issue, to cause execution of arbitary code or application to stop responding.
    last seen2020-06-01
    modified2020-06-02
    plugin id124021
    published2019-04-12
    reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/124021
    titleAdobe InDesign CC < 14.0.2 Arbitrary Code Execution Vulnerability (APSB19-23) (macOS)