Impact
A use‑after‑free flaw in Adobe InDesign Desktop lets an attacker execute arbitrary code when a victim opens a crafted file. The vulnerability arises after a freed memory block is incorrectly accessed, creating a dangling pointer that can be exploited. Classified as CWE‑416, achieving code execution elevates the attacker to the victim’s user context.
Affected Systems
Adobe InDesign Desktop versions 20.5.2, 21.2 and all earlier releases are vulnerable. The defect impacts only this desktop product and not other Adobe offerings.
Risk and Exploitability
With a CVSS score of 7.8, the flaw represents a high‑severity risk. No EPSS data or KEV listing is available, indicating that widespread exploitation has not yet been observed. The attack requires user interaction; the attacker must distribute a malicious InDesign file and persuade a user to open it.
OpenCVE Enrichment