Impact
A NULL Pointer Dereference in Adobe InDesign Desktop causes the application to crash when processing a maliciously crafted file. The failure manifests as a denial‑of‑service for the user, preventing normal use of InDesign until the program is restarted. The weakness is identified as CWE‑476.
Affected Systems
Adobe InDesign Desktop is affected; no specific versions are disclosed in the available data.
Risk and Exploitability
The CVSS base score of 5.5 indicates a moderate severity and suggests that exploitation is not trivial but can affect availability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying that no widespread active exploitation campaigns are known. Exploitation requires a victim to open a malicious file, so user interaction is the attack vector, reducing the likelihood of automated attacks but still presenting a risk in environments where users handle untrusted documents.
OpenCVE Enrichment