Skip to content

CVE-2021-39822 | InDesign

Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file..This CVE has a CVSS3.1 score of 7.8 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2021-39822
CVE StatePUBLISHED
BaseScore7.8
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
VersionNA

References for CVE-2021-39822 :
https://helpx.adobe.com/security/products/indesign/apsb21-73.html

Metric TypeMetric Score
AttackVector(AV)LOCAL
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)REQUIRED
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)HIGH
Integrity(I)HIGH