NULL Pointer Dereference in InDesign Desktop by Adobe
CVE-2025-30320

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 May 2025

What is CVE-2025-30320?

A NULL Pointer Dereference vulnerability exists in Adobe InDesign Desktop, impacting versions ID19.5.2 and ID20.2, as well as earlier versions. This vulnerability could allow an attacker to crash the application by requiring user interaction to open a specifically crafted file. The resulting exploitation leads to a denial-of-service, disrupting normal application functionality and service delivery.

Affected Version(s)

InDesign Desktop 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.