Junglewise Threat Intelligence

CVE-2026-21304: Adobe InDesign Desktop heap-based buffer overflow

CVE-2026-21304 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Adobe InDesign Desktop. Vendors: Adobe.

Executive brief

InDesign is a professional desktop publishing application used by designers and publishers to create layouts and print materials. A heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on a user's computer if they trick the user into opening a malicious document. This could lead to complete compromise of the user's system, including data theft and malware installation.

Technical details

InDesign Desktop versions 21.0, 19.5.5 and earlier contain a heap-based buffer overflow vulnerability in file parsing logic. The vulnerability is triggered when a user opens a specially crafted malicious file, causing a heap buffer to be overflowed. Exploitation requires user interaction (opening a malicious file) but no authentication. A successful exploit allows an attacker to execute arbitrary code in the context of the current user with the privileges of that user account.

Affected products

  • Adobe InDesign Desktop 21.0, 19.5.5 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats