CVE-2025-54224: InDesign Desktop | Use After Free (CWE-416)
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54224?
The CVE-2025-54224 vulnerability is classified as a critical issue due to the potential for arbitrary code execution.
How does CVE-2025-54224 affect Adobe InDesign Desktop?
CVE-2025-54224 affects Adobe InDesign Desktop versions 20.4 and 19.5.4 and earlier by allowing a Use After Free condition.
How can I mitigate the risks associated with CVE-2025-54224?
To mitigate CVE-2025-54224 risks, avoid opening untrusted files in Adobe InDesign Desktop.
What are the prerequisites for exploiting CVE-2025-54224?
Exploitation of CVE-2025-54224 requires the victim to open a specially crafted malicious file.
What versions of Adobe InDesign Desktop are vulnerable to CVE-2025-54224?
Adobe InDesign Desktop versions 20.4, 19.5.4 and earlier are vulnerable to CVE-2025-54224.