Impact
InDesign Desktop suffers an out‑of‑bounds read that occurs when a malicious file is parsed. The vulnerability can expose memory content beyond the allocated buffer and can be exploited to run arbitrary code under the credentials of the user opening the file. The flaw is catalogued as CWE‑125.
Affected Systems
Affected products include Adobe InDesign Desktop versions 20.5.2, 21.2, and all earlier releases. The issue is present in all builds prior to the security update described in Adobe's APBS26‑32 advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, though exploitation requires active user participation to open a crafted file. The EPSS score is not published and the vulnerability is not listed in CISA's KEV, suggesting limited known exploitation. Users should install the Adobe update or avoid opening untrusted documents to risk.
OpenCVE Enrichment