CVE-2019-7107 is a critical vulnerability affecting Adobe InDesign versions 14.0.1 and below, as well as versions 13.1.1 and below, across Windows and macOS platforms. This vulnerability stems from unsafe hyperlink processing, which, if exploited, could lead to arbitrary code execution. With a CVSS score of 9.8, it represents a severe risk due to its network-based attack vector, low attack complexity, and high potential for impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed in CISA's KEV catalog, its high FAUCET Risk Score and mention in media coverage indicate significant attention from the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.