CVE-2025-61815
7.8Adobe · InDesign Desktop
Adobe InDesign Desktop contains a use after free vulnerability that allows for arbitrary code execution when a user opens a specially crafted malicious file.
Executive summary
Adobe InDesign Desktop is affected by a critical use after free vulnerability that could allow an attacker to achieve arbitrary code execution via a malicious file.
Vulnerability
This is a use after free vulnerability (CWE-416) triggered when a user opens a maliciously crafted file. The vulnerability requires user interaction but, if successful, allows code execution in the context of the current user.
Business impact
Successful exploitation allows an attacker to execute arbitrary code with the permissions of the victim. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data exfiltration, or the deployment of persistent malware within the corporate environment.
Remediation
Immediate Action: Update Adobe InDesign Desktop to the latest patched version as provided in the Adobe security bulletin APSB25-106.
Proactive Monitoring: Monitor user workstations for suspicious InDesign process behavior or unexpected child process spawning initiated by the application.
Compensating Controls: Advise users to exercise extreme caution when opening InDesign files from untrusted or unknown sources until systems are fully patched.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk posed by this vulnerability is significant due to the potential for arbitrary code execution. Organizations should prioritize the deployment of the vendor-supplied patches to all affected endpoints immediately to prevent potential exploitation through malicious document campaigns.