CVE-2026-34697: InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not open InDesign files from untrusted or unknown sources; treat received InDesign files as potentially malicious because exploitation requires a victim to open a malicious file.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34697?
The severity of CVE-2026-34697 is rated as high with a score of 7.8.
How do I fix CVE-2026-34697?
To fix CVE-2026-34697, update Adobe InDesign to the latest version as recommended by the vendor.
What systems are affected by CVE-2026-34697?
CVE-2026-34697 affects Adobe InDesign versions 21.3, 20.5.3, and earlier.
What risk does CVE-2026-34697 pose?
CVE-2026-34697 poses a risk of arbitrary code execution, which can compromise the security of the affected system.
What kind of vulnerability is CVE-2026-34697?
CVE-2026-34697 is a stack-based buffer overflow vulnerability classified under CWE-121.