CVE Alert: CVE-2025-61824 – Adobe – InDesign Desktop
CVE-2025-61824
HIGHNo exploitation known
InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS v3.1 (7.8)
AV LOCAL · AC LOW · PR NONE · UI REQUIRED · S UNCHANGED
Vendor
Adobe
Product
InDesign Desktop
Versions
0 lte 19.5.5
CWE
CWE-122, Heap-based Buffer Overflow (CWE-122)
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published
2025-11-11T17:00:33.829Z
Updated
2025-11-11T17:00:33.829Z
AI Summary Analysis
Risk verdict
Why this matters
Most likely attack path
Who is most exposed
Detection ideas
- Crashes or memory-corruption events in InDesign after opening a file
- Unusual memory/CPU spikes during file load or document preview
- Unexpected process spawn or code execution activity linked to InDesign
- Alerts for crafted file attachments or documents masquerading as design assets
- Anomalous user activity following file opens (lateral access attempts or drive mapping)
Mitigation and prioritisation
- Apply the vendor patch/upgrade to the fixed build across all affected endpoints.
- Enforce least privilege, application control (AppLocker/WDAC), and sandboxing for InDesign; restrict auto-open of external design files.
- Enable robust EDR coverage and memory-detection rules for InDesign crashes.
- Validate and test patches in a staging environment before broad rollout; track remediation progress.
- If KEV true or EPSS ≥ 0.5, treat as priority 1.
Support Our Work
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
AI APIs OSINT driven New features
