Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the installation of malicious software in the context of the logged-in user.
Technical details
A Use After Free (CWE-416) vulnerability exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, which can be leveraged to execute arbitrary code. The attack vector is local, requiring a user to interact with a malicious file (UI:R). If successful, an attacker can achieve code execution with the privileges of the current user, potentially leading to full system compromise. Adobe has addressed this in newer versions; users should refer to APSB26-58 for patching details.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: advisory: Adobe published security bulletin APSB26-58
- 2026-06-09: disclosed: NVD published the CVE record