Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a vulnerability that can cause the application to crash. An attacker could trick a user into opening a specially crafted file, leading to a loss of unsaved work and a disruption of business operations. This issue primarily impacts the availability of the software rather than the confidentiality of customer data.
Technical details
A NULL Pointer Dereference vulnerability (CWE-476) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw is triggered when the application attempts to read or process a specifically crafted malicious file. An attacker can exploit this by distributing a malicious document that, when opened by a user, causes the application to crash (Denial of Service). The attack vector is local and requires user interaction (UI:R). No privilege escalation or data exfiltration is associated with this specific vulnerability. Adobe has addressed this in security bulletin APSB26-58.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory