Executive brief
Adobe InDesign is a professional page layout and design application used by marketers, designers, and publishers to create printed and digital documents. A heap buffer overflow vulnerability in InDesign Desktop versions 21.1, 20.5.1 and earlier can be exploited by convincing a user to open a malicious file, causing the application to crash and disrupting work on critical design projects.
Technical details
This is a heap-based buffer overflow vulnerability in Adobe InDesign Desktop that occurs when processing maliciously crafted input. The vulnerability is reachable through user interaction—specifically by opening a malicious file—and does not require authentication or network connectivity. Successful exploitation results in denial-of-service by crashing the application; arbitrary code execution is not confirmed. Adobe has released patches to address this vulnerability in versions after 21.1 and 20.5.1.
Affected products
- Adobe InDesign Desktop 21.1, 20.5.1 and earlier
Timeline
- 2026-02-10: disclosed