Executive brief
Adobe InDesign Desktop is a professional design and layout software used to create publications, marketing materials, and digital documents. A memory exposure vulnerability allows attackers to read sensitive data from the application's memory when a user opens a malicious file. This could lead to exposure of passwords, encryption keys, or other confidential information processed by the application.
Technical details
An out-of-bounds read vulnerability exists in InDesign Desktop's file parsing logic, allowing an attacker to read memory beyond allocated buffer boundaries. The vulnerability affects versions 21.0, 19.5.5, and earlier. Exploitation requires user interaction—a victim must open a specially crafted malicious file (likely a .indd or related format). An attacker can use this to access sensitive information resident in application memory. A patch from Adobe is expected to address this issue.
Affected products
- Adobe InDesign Desktop 21.0, 19.5.5 and earlier
Timeline
- 2026-01-13: disclosed