Impact
A flaw in Adobe InDesign Desktop allows an attacker to read data from a memory location that has not been initialized, which the software may then use to control program flow. This results in the potential execution of arbitrary code with the privileges of the user who opens a compromised file. The weakness is a classic case of Access of Uninitialized Pointer (CWE-824).
Affected Systems
Adobe InDesign Desktop versions 21.0, 19.5.5 and all earlier releases on macOS and Windows are affected. Any user who installs these versions and opens files from untrusted sources can be exposed to the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates significant severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation has not been widely observed yet. Nevertheless, the vulnerability requires user interaction—an attacker must get the victim to open a specially crafted file. Once that occurs, the attacker could execute code within the victim’s user session, potentially giving them the same rights as the user. Because the attack vector is local with required user action, the risk is moderate but non‑negligible, especially in environments where users open files from remote or untrusted sources.
OpenCVE Enrichment