Executive brief
Adobe InDesign is a professional design and layout software used by creative teams to produce digital and print media. A heap-based buffer overflow vulnerability allows attackers to achieve arbitrary code execution on a user's computer by tricking them into opening a specially crafted malicious file. This could enable unauthorized access to sensitive project files, system data, and provide a foothold for further attacks.
Technical details
A heap-based buffer overflow vulnerability exists in Adobe InDesign that permits arbitrary code execution within the context of the user running the application. The vulnerability is triggered when a user opens a crafted malicious file, indicating the flaw likely resides in file parsing or processing logic. The attack requires user interaction (opening a file) but no authentication bypass or elevated privileges are necessary. An attacker can achieve arbitrary code execution on the victim's system with the privileges of the logged-in user. Adobe has addressed this issue in patched versions beyond 19.5.5 and 21.0.
Affected products
- Adobe InDesign 19.5.5, 21.0 and earlier
Timeline
- 2026-01-13: disclosed