Impact
A heap‑based buffer overflow exists in Adobe InDesign Desktop versions 20.5.2, 21.2 and earlier, allowing an attacker to crash or disrupt the application. This vulnerability can cause denial‑of‑service and leads to application instability. The weakness is a classic buffer overflow (CWE‑122) that corrupts memory on the heap.
Affected Systems
Adobe InDesign Desktop is affected. Vulnerable releases include version 20.5.2, 21.2, and all earlier releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. Exploitation requires user interaction, namely opening a malicious InDesign file; thus the attack vector is local. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation at present. Nevertheless, the impact of a denial‑of‑service is significant for end‑users and can disrupt workflow.
OpenCVE Enrichment