Description
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-06-09
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A NULL Pointer Dereference flaw exists in Adobe InDesign Desktop, allowing attackers to trigger a deliberate crash when a malicious file is opened. The software aborts execution, causing a local denial‑of‑service condition that defeats only the application, not the underlying operating system. This weakness does not provide code execution or privilege escalation but can force users to restart the program and lose unsaved work.

Affected Systems

Adobe InDesign Desktop versions 21.3, 20.5.3, and all earlier releases are affected. The problem is limited to the desktop edition and does not impact other Adobe Creative Cloud applications.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. Because exploitation requires an end‑user to open a crafted file, the likelihood of attack depends on phishing or social engineering. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. Nonetheless, any user interacting with unknown documents should be cautious, as a successful exploit results in an application crash and potential disruption of workflow.

Generated by OpenCVE AI on June 9, 2026 at 20:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe InDesign Desktop update that includes the null pointer dereference fix (see Adobe’s security advisory for the applicable release).
  • Until the update is applied, avoid opening or executing any InDesign files received from untrusted or unknown sources to prevent the crash condition.
  • Configure your desktop environment to run InDesign within a sandbox or restricted application context so that a crash cannot propagate to other critical system components.

Generated by OpenCVE AI on June 9, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe indesign
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe indesign
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 10 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe indesign Desktop
Vendors & Products Adobe
Adobe indesign Desktop

Tue, 09 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 18:00:00 +0000

Type Values Removed Values Added
Description InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title InDesign Desktop | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Indesign Indesign Desktop
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T18:37:34.156Z

Reserved: 2026-03-30T17:30:36.498Z

Link: CVE-2026-34704

cve-icon Vulnrichment

Updated: 2026-06-09T18:36:16.079Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T18:16:42.583

Modified: 2026-06-10T13:01:24.790

Link: CVE-2026-34704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T01:30:17Z

Weaknesses