CVE-2025-21157
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 11, 2025
CWE ID 787
Summary
CVE-2025-21157 is a newly disclosed vulnerability affecting Adobe InDesign Desktop versions ID20.0, ID19.5.1, and earlier. This issue involves an out-of-bounds write vulnerability, which allows malicious code execution in the context of the current user. To exploit this weakness, a victim must open a specially crafted file, making it a user-interactive threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- InDesign Desktop
Affected Vendors
- Adobe