Executive brief
Adobe InDesign Desktop, a desktop publishing application, contains a null pointer dereference vulnerability that can be triggered when opening a malicious file. An attacker can exploit this flaw to crash the application, causing a denial-of-service condition and disrupting the user's work. Exploitation requires the victim to open a specially crafted file.
Technical details
A null pointer dereference in InDesign Desktop allows an attacker to trigger an application crash through a malicious file. The vulnerability requires user interaction (opening a crafted document) and does not permit remote code execution. The flaw results in denial-of-service by making the application unavailable.
Affected products
- Adobe InDesign Desktop
Timeline
- 2026-09-22: disclosed