Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data or the installation of malicious software.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw occurs when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. The attack vector is local, requiring the victim to manually open a malicious document (User Interaction: Required). Adobe has addressed this issue in updated versions of the software.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory