CVE-2025-61824

7.8

Adobe · InDesign Desktop

Adobe InDesign Desktop contains a heap-based buffer overflow vulnerability that may allow a local attacker to achieve arbitrary code execution through a maliciously crafted file.

Executive summary

Adobe InDesign Desktop versions 19.5.5 and earlier are vulnerable to a heap-based buffer overflow that could lead to arbitrary code execution upon opening a malicious file.

Vulnerability

This is a heap-based buffer overflow (CWE-122) triggered when the application processes a specifically crafted file. Exploitation requires user interaction, as the victim must open the malicious document, at which point code execution occurs within the context of the current user.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting a High severity rating due to the potential for complete loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code on the victim's machine, which could lead to unauthorized data access, the installation of malware, or full system compromise.

Remediation

Immediate Action: Update Adobe InDesign Desktop to the latest version provided by the vendor in the security advisory APSB25-106.

Proactive Monitoring: Security teams should monitor endpoint activity for unexpected child processes spawned by the InDesign application.

Compensating Controls: Ensure that endpoint protection software is active and configured to scan files upon opening, and advise users to exercise caution when opening documents from untrusted sources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a severe risk to internal workstations. Administrators should prioritize the deployment of the vendor-supplied patch to all affected Adobe InDesign installations to eliminate this attack vector.

More Adobe CVEs

Sources