First published: Tue Mar 11 2025(Updated: )
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe InDesign | <20.1 | |
Adobe InDesign | >19.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27179 has a medium severity rating due to its potential to cause denial-of-service conditions.
To remediate CVE-2025-27179, users should update Adobe InDesign Desktop to version 20.2 or later.
CVE-2025-27179 affects Adobe InDesign Desktop versions 20.1, 19.5.2 and earlier.
CVE-2025-27179 is a NULL pointer dereference vulnerability that can lead to application crashes.
An attacker exploiting CVE-2025-27179 can cause a denial-of-service condition by crashing the application.