Impact
This vulnerability is a NULL Pointer Dereference in Adobe InDesign Desktop that causes the application to crash. The result is a denial‑of‑service condition that prevents the program from running normally. It arises when a specific memory reference is null and the software attempts to read or write through it, in line with CWE‑476. The impact is limited to application availability and does not provide attacker control over the host system.
Affected Systems
Adobe InDesign Desktop is affected. No specific version details are provided, so all installations of Adobe InDesign Desktop are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate level of severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low or unclear public exploitation likelihood. Exploitation requires user interaction: a victim must open a malicious file crafted by the attacker. The attack vector is therefore local or user‑initiated rather than remote.
OpenCVE Enrichment