Impact
A NULL Pointer Dereference flaw exists in Adobe InDesign Desktop, allowing attackers to trigger a deliberate crash when a malicious file is opened. The software aborts execution, causing a local denial‑of‑service condition that defeats only the application, not the underlying operating system. This weakness does not provide code execution or privilege escalation but can force users to restart the program and lose unsaved work.
Affected Systems
Adobe InDesign Desktop versions 21.3, 20.5.3, and all earlier releases are affected. The problem is limited to the desktop edition and does not impact other Adobe Creative Cloud applications.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. Because exploitation requires an end‑user to open a crafted file, the likelihood of attack depends on phishing or social engineering. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. Nonetheless, any user interacting with unknown documents should be cautious, as a successful exploit results in an application crash and potential disruption of workflow.
OpenCVE Enrichment