InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Title | InDesign Desktop | Heap-based Buffer Overflow (CWE-122) | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-04-14T16:45:54.103Z
Updated: 2026-04-14T19:37:43.093Z
Reserved: 2026-02-18T22:02:41.395Z
Link: CVE-2026-27286
Updated: 2026-04-14T19:35:43.900Z
Status : Received
Published: 2026-04-14T17:16:48.357
Modified: 2026-04-14T17:16:48.357
Link: CVE-2026-27286
No data.