Description


InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Related CPE's


a

adobe

indesign

2


Weaknesses



CWE-824

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-13T19:16:25.200Z

25 hours ago

Last modified

2026-01-14T19:28:06.030Z

1 hour ago