CVE-2026-21357
7.8Adobe · InDesign Desktop
Adobe InDesign Desktop is affected by a heap-based buffer overflow vulnerability that could allow an attacker to achieve arbitrary code execution through a maliciously crafted file.
Executive summary
A heap-based buffer overflow in Adobe InDesign Desktop allows for arbitrary code execution when a user opens a malicious file.
Vulnerability
This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the application processes a specially crafted file. Exploitation requires user interaction: a victim must be enticed to open the malicious document.
Business impact
The ability for an attacker to achieve arbitrary code execution poses a severe threat to data confidentiality, integrity, and system availability. With a CVSS score of 7.8, this high-severity flaw could lead to full system compromise or the installation of persistent malware within the corporate environment.
Remediation
Immediate Action: Update Adobe InDesign Desktop to version 21.2 or 20.5.2 immediately to apply the vendor-supplied security patch.
Proactive Monitoring: Monitor workstation endpoint logs for abnormal application crashes or unexpected child processes spawning from the InDesign executable.
Compensating Controls: Implement robust email filtering and browser-based file scanning to prevent users from downloading or opening untrusted or unsolicited InDesign documents.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to end-user workstations. Organizations should prioritize patching all instances of InDesign Desktop across their environments. Users should be cautioned against opening files from untrusted sources until the update is successfully applied.