First published: Mon Jun 28 2021(Updated: )
Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe InDesign 2025 | <=16.0 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21098 is classified as critical due to its potential for remote code execution.
To fix CVE-2021-21098, update Adobe InDesign to version 16.1 or later.
CVE-2021-21098 affects all users of Adobe InDesign version 16.0 and earlier.
Yes, CVE-2021-21098 can be exploited remotely by an unauthenticated attacker.
CVE-2021-21098 can enable attackers to achieve remote code execution in the context of the current user.