CVE-2024-53952
Published: 10 December 2024
Summary
CVE-2024-53952 is a medium-severity NULL Pointer Dereference (CWE-476) vulnerability in Adobe Indesign. Its CVSS base score is 5.5 (Medium).
Operationally, ranked at the 29.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-52207
Vulnerability details
InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation…
more
of this issue requires user interaction in that a victim must open a malicious file.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.