- Description
 - InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
 - Source
 - psirt@adobe.com
 - NVD status
 - Analyzed
 - Products
 - indesign
 
CVSS 3.1
- Type
 - Primary
 - Base score
 - 5.5
 - Impact score
 - 3.6
 - Exploitability score
 - 1.8
 - Vector string
 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
 - Severity
 - MEDIUM
 
- psirt@adobe.com
 - CWE-476
 
- Hype score
 - Not currently trending
 
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "BFAA287E-8E00-402E-A33F-E3C8CBC86618",
            "versionEndExcluding": "19.5.2"
          },
          {
            "criteria": "cpe:2.3:a:adobe:indesign:20.0:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "DEF1D0A8-9DAD-403E-800C-FBFB8F9C0F41"
          }
        ],
        "operator": "OR"
      },
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
            "vulnerable": false,
            "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
            "vulnerable": false,
            "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
          }
        ],
        "operator": "OR"
      }
    ],
    "operator": "AND"
  }
]