peter bassill · operator
$ cve CVE-2019-7107 JSON

CVE-2019-7107

9.8
CRITICAL · CVSS 3.1 · EPSS 28.9% (pctl 98)

Patch early

EPSS 28.9% — above the 10% action threshold.

Description

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS28.94% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploitnone known
Published2019-05-23
Last modified2026-06-17

Affected (3)

VendorProduct
adobeindesign
applemac os x
microsoftwindows

References

→ the Explorer  ·  watch your stack  ·  NVD