Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or system compromise.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. The attack vector is local, requiring the victim to manually open a malicious document (User Interaction: Required). Adobe has addressed this issue in security bulletin APSB26-58.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory