Out-of-Bounds Read Vulnerability in InDesign by Adobe
CVE-2025-47105

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 June 2025

What is CVE-2025-47105?

InDesign Desktop versions ID20.2, ID19.5.3, and earlier contain an out-of-bounds read vulnerability that could allow attackers to access sensitive memory content. This vulnerability can be exploited when a victim opens a specifically crafted malicious file, potentially enabling the attacker to bypass security measures like Address Space Layout Randomization (ASLR). As user interaction is required for exploitation, it emphasizes the need for caution while handling unknown files.

Affected Version(s)

InDesign Desktop 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.