CVE-2026-21357

7.8

Adobe · InDesign Desktop

Adobe InDesign Desktop is affected by a heap-based buffer overflow vulnerability that could allow an attacker to achieve arbitrary code execution through a maliciously crafted file.

Executive summary

A heap-based buffer overflow in Adobe InDesign Desktop allows for arbitrary code execution when a user opens a malicious file.

Vulnerability

This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the application processes a specially crafted file. Exploitation requires user interaction: a victim must be enticed to open the malicious document.

Business impact

The ability for an attacker to achieve arbitrary code execution poses a severe threat to data confidentiality, integrity, and system availability. With a CVSS score of 7.8, this high-severity flaw could lead to full system compromise or the installation of persistent malware within the corporate environment.

Remediation

Immediate Action: Update Adobe InDesign Desktop to version 21.2 or 20.5.2 immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Monitor workstation endpoint logs for abnormal application crashes or unexpected child processes spawning from the InDesign executable.

Compensating Controls: Implement robust email filtering and browser-based file scanning to prevent users from downloading or opening untrusted or unsolicited InDesign documents.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant risk to end-user workstations. Organizations should prioritize patching all instances of InDesign Desktop across their environments. Users should be cautioned against opening files from untrusted sources until the update is successfully applied.

More Adobe CVEs

Sources