Heap-based Buffer Overflow in InDesign Desktop by Adobe
CVE-2026-27285
5.5MEDIUM
What is CVE-2026-27285?
InDesign Desktop versions 20.5.2, 21.2, and earlier are exposed to a heap-based buffer overflow vulnerability that may compromise application stability. Attackers can exploit this flaw to crash the application or curtail its functionality by leveraging malicious files. Notably, exploitation necessitates user interaction, as the targeted individual must open a crafted file designed to trigger the overflow.
Affected Version(s)
InDesign Desktop 0 <= 21.2