CVE-2025-27176
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-27176 is a NULL Pointer Dereference vulnerability that affects Adobe InDesign Desktop versions ID20.1, ID19.5.2, and earlier. This issue can lead to an application denial-of-service, as an attacker can exploit it to cause the application to crash. The vulnerability requires user interaction, meaning a victim must open a specially crafted file for exploitation to occur. Successful exploitation could result in a denial-of-service condition for the InDesign application. Users are advised to update their software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- InDesign Desktop
Affected Vendors
- Adobe