Impact
A heap-based buffer overflow in Adobe InDesign Desktop allows an attacker to execute arbitrary code with the privileges of the user who opens a crafted file. The vulnerability is classified under CWE-122.
Affected Systems
Adobe InDesign Desktop versions 20.5.2, 21.2 and all earlier releases are affected by this vulnerability.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious file, so the attack vector is local and relies on social engineering.
OpenCVE Enrichment