Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted, malicious InDesign file. If successful, the attacker could run unauthorized commands or install software with the same permissions as the logged-in user.
Technical details
A heap-based buffer overflow (CWE-122) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The vulnerability is triggered when the application improperly handles memory allocation while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is classified as local with required user interaction (AV:L/UI:R). Adobe has addressed this issue in updated versions of the software.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: advisory: Initial disclosure by Adobe and NVD publication