Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-04-23T17:06:07.146Z
Reserved: 2022-08-18T00:00:00.000Z
Link: CVE-2022-38416
Updated: 2024-08-03T10:54:03.461Z
Status : Modified
Published: 2022-09-16T18:15:16.630
Modified: 2024-11-21T07:16:25.973
Link: CVE-2022-38416
No data.