First published: Tue Feb 11 2025(Updated: )
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe InDesign | <19.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-21158 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2025-21158, update Adobe InDesign Desktop to version 19.5 or later.
CVE-2025-21158 affects Adobe InDesign Desktop versions 20.0, 19.5.1, and earlier.
CVE-2025-21158 is an Integer Underflow vulnerability that may lead to arbitrary code execution.
Exploitation of CVE-2025-21158 requires user interaction to be successful.