Impact
Adobe InDesign Desktop versions 20.5.2, 21.2 and earlier contain a heap‑based buffer overflow that can lead to arbitrary code execution within the context of the user who opens a malicious file. The vulnerability stems from an improperly bounded heap allocation and is classified as CWE‑122.
Affected Systems
The affected product is Adobe InDesign Desktop on Windows and macOS, specifically versions 20.5.2, 21.2, and earlier releases of the application.
Risk and Exploitability
The CVSS base score of 7.8 marks this as a high‑severity issue, while an EPSS score of less than 1 % indicates a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a single user interaction: the victim must open a crafted InDesign file, which can be delivered via phishing or other social engineering. Once the file is opened, arbitrary code with the victim’s privileges, presenting a serious risk if malicious documents are circulated.
OpenCVE Enrichment