CVE-2026-27284

7.8

Adobe · InDesign Desktop

Adobe InDesign Desktop is susceptible to an out-of-bounds read vulnerability when parsing crafted files, potentially allowing an attacker to execute arbitrary code in the context of the user.

Executive summary

Adobe InDesign Desktop versions 21.2 and 20.5.2 and earlier are vulnerable to remote code execution via a maliciously crafted file, posing a significant risk to user workstations.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) occurring during the parsing of malformed files. Successful exploitation requires user interaction, as the victim must open a specifically crafted file provided by an attacker.

Business impact

Successful exploitation allows an attacker to execute arbitrary code within the security context of the current user, which can lead to full system compromise, data theft, or installation of persistent malware. With a CVSS score of 7.8, this high-severity vulnerability represents a substantial threat to organizational integrity, particularly for environments where users frequently handle untrusted documents.

Remediation

Immediate Action: Update Adobe InDesign Desktop to version 21.3 or 20.5.3 immediately to incorporate the vendor-provided security patches.

Proactive Monitoring: Monitor endpoint activity for suspicious processes spawned by InDesign, such as shells or unexpected network connections originating from the application.

Compensating Controls: Implement file-type filtering and restrict the execution of untrusted InDesign files from unknown or unverified sources until updates are applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations must prioritize patching all instances of Adobe InDesign Desktop to the identified fixed versions. Given the potential for code execution, ensuring that users do not open files from untrusted sources is a vital interim security practice while the update deployment is finalized across the enterprise.

More Adobe CVEs

Sources