Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or system compromise.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw is triggered when the application improperly handles memory during the processing of a specially crafted file. An attacker can exploit this by convincing a victim to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R) but no prior privileges (PR:N). Adobe has addressed this issue in updated versions of the software.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier versions
Timeline
- 2026-06-09: advisory: Adobe published security bulletin APSB26-58
- 2026-06-09: disclosed