QID 378662

Date Published: 2023-07-12

QID 378662: Adobe InDesign Arbitrary Code Execution Vulnerability (APSB23-38)

Adobe InDesign is a desktop publishing software application developed and marketed by Adobe Systems.

Affected Versions:
Adobe InDesign - ID18.3 and earlier version. Windows and MacOS
Adobe InDesign - ID17.4.1 and earlier version. Windows and MacOS

QID Detection Logic:(Authenticated)
This QID checks vulnerable versions of Adobe InDesign.

Successful exploitation could lead to arbitrary code execution and memory leak.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution

    Adobe has released fix to address this issue. Customers are advised to refer to APSB23-38 for updates pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    APSB23-38 URL Logo helpx.adobe.com//security/products/indesign/apsb23-38.html