Impact
An out‑of‑bounds read in InDesign Desktop can cause memory exposure, allowing an attacker to read sensitive data from memory. The flaw requires a victim to open a malicious file, therefore user interaction is necessary for exploitation.
Affected Systems
Adobe InDesign Desktop, versions 21.0, 19.5.5 and all earlier releases are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate severity, and an EPSS score of less than 1%, reflecting a low likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires that a user opens a specially crafted InDesign file, so the attack vector is primarily local input exploitation via a crafted file.
OpenCVE Enrichment