Description
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-01-13
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution in user context
Action: Immediate Patch
AI Analysis

Impact

A flaw in Adobe InDesign Desktop allows an attacker to read data from a memory location that has not been initialized, which the software may then use to control program flow. This results in the potential execution of arbitrary code with the privileges of the user who opens a compromised file. The weakness is a classic case of Access of Uninitialized Pointer (CWE-824).

Affected Systems

Adobe InDesign Desktop versions 21.0, 19.5.5 and all earlier releases on macOS and Windows are affected. Any user who installs these versions and opens files from untrusted sources can be exposed to the vulnerability.

Risk and Exploitability

The CVSS score of 7.8 indicates significant severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation has not been widely observed yet. Nevertheless, the vulnerability requires user interaction—an attacker must get the victim to open a specially crafted file. Once that occurs, the attacker could execute code within the victim’s user session, potentially giving them the same rights as the user. Because the attack vector is local with required user action, the risk is moderate but non‑negligible, especially in environments where users open files from remote or untrusted sources.

Generated by OpenCVE AI on April 18, 2026 at 06:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe InDesign Desktop update that removes the uninitialized pointer flaw.
  • Disable automatic execution of JavaScript and other extensions in InDesign through the Preferences dialog or by uninstalling unnecessary plug‑ins.
  • Run InDesign within an OS‑level sandbox or with the least privilege necessary to limit potential damage if the flaw is exploited.

Generated by OpenCVE AI on April 18, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 14 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Microsoft
Microsoft windows

Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe indesign
Vendors & Products Adobe
Adobe indesign

Tue, 13 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 19:00:00 +0000

Type Values Removed Values Added
Description InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
Weaknesses CWE-824
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-02-26T15:04:15.877Z

Reserved: 2025-12-12T22:01:18.188Z

Link: CVE-2026-21275

cve-icon Vulnrichment

Updated: 2026-01-13T19:05:03.635Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T19:16:25.030

Modified: 2026-01-14T19:28:03.193

Link: CVE-2026-21275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T06:45:23Z

Weaknesses