Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a vulnerability that can cause the application to crash. An attacker could trick a user into opening a specially crafted file, leading to a denial-of-service condition. This would result in the loss of unsaved work and temporary disruption of design operations.
Technical details
A NULL Pointer Dereference vulnerability (CWE-476) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw is triggered when the application attempts to read or process a malformed file, leading to an immediate application crash. The attack vector is local, requiring the victim to manually open a malicious document (User Interaction required). Successful exploitation results in a denial-of-service (DoS) condition. Users are advised to update to the latest versions provided by Adobe to mitigate this risk.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory