Description
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-06-09
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A NULL Pointer Dereference flaw exists in Adobe InDesign Desktop, allowing attackers to trigger a deliberate crash when a malicious file is opened. The software aborts execution, causing a local denial‑of‑service condition that defeats only the application, not the underlying operating system. This weakness does not provide code execution or privilege escalation but can force users to restart the program and lose unsaved work.

Affected Systems

Adobe InDesign Desktop versions 21.3, 20.5.3, and all earlier releases are affected. The problem is limited to the desktop edition and does not impact other Adobe Creative Cloud applications.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. Because exploitation requires an end‑user to open a crafted file, the likelihood of attack depends on phishing or social engineering. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. Nonetheless, any user interacting with unknown documents should be cautious, as a successful exploit results in an application crash and potential disruption of workflow.

Generated by OpenCVE AI on June 9, 2026 at 20:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe InDesign Desktop update that includes the null pointer dereference fix (see Adobe’s security advisory for the applicable release).
  • Until the update is applied, avoid opening or executing any InDesign files received from untrusted or unknown sources to prevent the crash condition.
  • Configure your desktop environment to run InDesign within a sandbox or restricted application context so that a crash cannot propagate to other critical system components.

Generated by OpenCVE AI on June 9, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 18:00:00 +0000

Type Values Removed Values Added
Description InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title InDesign Desktop | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T18:37:34.156Z

Reserved: 2026-03-30T17:30:36.498Z

Link: CVE-2026-34704

cve-icon Vulnrichment

Updated: 2026-06-09T18:36:16.079Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-09T18:16:42.583

Modified: 2026-06-09T19:30:24.713

Link: CVE-2026-34704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T20:15:07Z

Weaknesses