CVE-2020-9730 is a memory corruption vulnerability affecting Adobe InDesign 15.1.1 and earlier versions on macOS. It carries a CVSS score of 7.8 (High) due to an out-of-bounds memory access triggered by an insecurely handled malicious .indd file, potentially leading to arbitrary code execution in the context of the current user. While user interaction is required (UI:R) to open the malicious file, the attack complexity is low (AC:L). There is no evidence of active exploitation (KEV: No), nor are there public exploits available on Metasploit or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15.1.1CPE matchmatch criteria | cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.