CVE-2025-61824
7.8Adobe · InDesign Desktop
Adobe InDesign Desktop contains a heap-based buffer overflow vulnerability that may allow a local attacker to achieve arbitrary code execution through a maliciously crafted file.
Executive summary
Adobe InDesign Desktop versions 19.5.5 and earlier are vulnerable to a heap-based buffer overflow that could lead to arbitrary code execution upon opening a malicious file.
Vulnerability
This is a heap-based buffer overflow (CWE-122) triggered when the application processes a specifically crafted file. Exploitation requires user interaction, as the victim must open the malicious document, at which point code execution occurs within the context of the current user.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting a High severity rating due to the potential for complete loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code on the victim's machine, which could lead to unauthorized data access, the installation of malware, or full system compromise.
Remediation
Immediate Action: Update Adobe InDesign Desktop to the latest version provided by the vendor in the security advisory APSB25-106.
Proactive Monitoring: Security teams should monitor endpoint activity for unexpected child processes spawned by the InDesign application.
Compensating Controls: Ensure that endpoint protection software is active and configured to scan files upon opening, and advise users to exercise caution when opening documents from untrusted sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability poses a severe risk to internal workstations. Administrators should prioritize the deployment of the vendor-supplied patch to all affected Adobe InDesign installations to eliminate this attack vector.