Impact
An out‑of‑bounds read in Adobe InDesign Desktop allows an attacker to read data beyond the intended buffer limits, potentially exposing memory contents such as credentials, cryptographic keys, or other sensitive information and compromising data confidentiality. The vulnerability is classified as CWE‑125 and is specifically present in versions 21.1, 20.5.1 and earlier.
Affected Systems
Adobe InDesign Desktop on macOS and Windows is affected. All releases up to and including version 21.1 and 20.5.1 contain the flaw, which arises when the program parses certain document files.
Risk and Exploitability
The CVSS score of 5.5 categorizes the vulnerability as moderate, while the EPSS score of less than 1% indicates a very low likelihood of exploitation and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a maliciously crafted file, implying a local or social‑engineering attack vector. A successful exploit would disclose memory content, potentially revealing user credentials or confidential document data, but it does not grant code execution or cause service disruption.
OpenCVE Enrichment