CVE-2026-34703: InDesign Desktop | NULL Pointer Dereference (CWE-476)
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not open InDesign files from untrusted or unknown sources. Treat .indd and related files received by email or download as potentially malicious and only open them in a controlled environment.
- Compensating control
Open untrusted InDesign files only within isolated environments (sandbox, VM, or dedicated analysis workstation). Consider disabling automatic file previews/thumbnails and blocking InDesign attachments at email gateways or via file-type ACLs to reduce accidental execution.
- Operational
Monitor Adobe security advisories for InDesign Desktop and apply vendor-provided fixes or patches as soon as they are released for affected versions (noting that versions 21.3, 20.5.3 and earlier are affected).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34703?
The severity of CVE-2026-34703 is rated as medium with a score of 5.5.
What impact does CVE-2026-34703 have on Adobe InDesign Desktop?
CVE-2026-34703 can lead to a denial-of-service condition by causing the application to crash.
How can I fix CVE-2026-34703?
To fix CVE-2026-34703, update Adobe InDesign Desktop to the latest version available.
What versions of Adobe InDesign Desktop are affected by CVE-2026-34703?
Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by CVE-2026-34703.
What type of vulnerability is CVE-2026-34703?
CVE-2026-34703 is a NULL Pointer Dereference vulnerability, classified under CWE-476.