CVE-2025-27176

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 476

Summary

CVE-2025-27176 is a NULL Pointer Dereference vulnerability that affects Adobe InDesign Desktop versions ID20.1, ID19.5.2, and earlier. This issue can lead to an application denial-of-service, as an attacker can exploit it to cause the application to crash. The vulnerability requires user interaction, meaning a victim must open a specially crafted file for exploitation to occur. Successful exploitation could result in a denial-of-service condition for the InDesign application. Users are advised to update their software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share