CVE-2025-61814
7.8Adobe · InDesign Desktop
Adobe InDesign Desktop contains a Use After Free vulnerability that allows for arbitrary code execution when a user opens a specially crafted malicious file.
Executive summary
Adobe InDesign Desktop is affected by a critical Use After Free vulnerability that could lead to arbitrary code execution if a user opens a malicious file.
Vulnerability
This is a Use After Free vulnerability (CWE-416) triggered when the application processes a malformed file. The attacker requires user interaction to open the malicious document, at which point arbitrary code execution occurs within the context of the current user.
Business impact
The potential for arbitrary code execution presents a significant risk to organizational endpoints, potentially allowing attackers to gain control over local workstations, exfiltrate sensitive document data, or pivot further into the internal network. With a CVSS score of 7.8, this vulnerability is classified as High severity, as it directly compromises the confidentiality, integrity, and availability of the host system.
Remediation
Immediate Action: Update Adobe InDesign Desktop to the latest patched version as specified in Adobe Security Bulletin APSB25-106.
Proactive Monitoring: Monitor endpoint security logs for abnormal application crashes or unexpected child processes spawning from InDesign, which may indicate an exploitation attempt.
Compensating Controls: Implement strict email filtering and document attachment policies to prevent users from opening untrusted or unsolicited files, and ensure endpoint protection software is active and updated.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the risk of arbitrary code execution, organizations should prioritize patching Adobe InDesign Desktop across all user workstations. Users should be advised to exercise caution when opening files from untrusted or unknown sources until the security updates are fully deployed across the environment.