Junglewise Threat Intelligence

CVE-2026-34704: Adobe InDesign NULL Pointer Dereference denial-of-service

CVE-2026-34704 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Adobe InDesign Desktop. Vendors: Adobe.

Executive brief

Adobe InDesign, a professional desktop publishing software, is affected by a vulnerability that can cause the application to crash. An attacker could trick a user into opening a specially crafted file, leading to a denial-of-service condition. This would result in the loss of unsaved work and temporary disruption of design operations.

Technical details

A NULL Pointer Dereference vulnerability (CWE-476) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw is triggered when the application attempts to read or process a malformed file, leading to an immediate application crash. The attack vector is local, requiring the victim to manually open a malicious document (User Interaction required). Successful exploitation results in a denial-of-service (DoS) condition. Users are advised to update to the latest versions provided by Adobe to mitigate this risk.

Affected products

  • Adobe InDesign Desktop 21.3, 20.5.3 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats