Heap-based Buffer Overflow in Adobe InDesign Affecting Multiple Versions
CVE-2025-27177

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
11 March 2025

Summary

A vulnerability in Adobe InDesign Desktop versions ID20.1, ID19.5.2, and earlier allows for a Heap-based Buffer Overflow, potentially leading to arbitrary code execution if a user opens a malicious file. Successful exploitation necessitates user interaction, which raises security concerns for individuals and organizations using this software. It is essential to take preventive measures to mitigate risks associated with this vulnerability.

Affected Version(s)

InDesign Desktop 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.