Impact
The flaw is a heap-based buffer overflow in the desktop version of Adobe InDesign. A crafted malicious file can exploit the overflow to execute arbitrary code in the context of the user who opens the file. This leads to a loss of confidentiality, integrity, and availability for the affected system because the attacker can run any code with the victim’s privileges.
Affected Systems
Adobe InDesign Desktop applications are impacted. Versions 20.5.2, 21.2 and all earlier releases are vulnerable. The vulnerability does not affect newer releases beyond those listed.
Risk and Exploitability
The CVSS rating of 7.8 reflects a moderate to high severity. EPSS data is not available, and the issue is not present in CISA’s Known Exploited Vulnerabilities catalog. Exploitation requires local user interaction: an attacker must entice the victim to open a malicious file. Once executed, the attacker gains the victim’s user privileges, allowing code execution, data exfiltration, or further malware deployment. Users should consider this a significant risk if they frequently handle untrusted documents.
OpenCVE Enrichment