Impact
InDesign Desktop versions 21.1, 20.5.1 and earlier suffer from a heap‑based buffer overflow that allows arbitrary code execution when a user opens a malicious file. The flaw is identified as CWE-122 and CWE-787. Exploitation causes code to run with the victim’s user privileges, potentially compromising the entire machine.
Affected Systems
Adobe InDesign Desktop on both macOS and Windows platforms is affected. The vulnerability exists in releases 21.1, 20.5.1 and earlier. All installations running the affected versions on these operating systems must be updated to a patched release.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. The EPSS score is below 1%, signifying a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. The required user interaction – opening a crafted file – limits automated exploitation but still poses a significant risk in environments where users frequently handle untrusted documents. Effective mitigation requires immediate patching.
OpenCVE Enrichment