CVE Alert: CVE-2025-61815 – Adobe – InDesign Desktop

CVE-2025-61815

HIGHNo exploitation known

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS v3.1 (7.8)
AV LOCAL · AC LOW · PR NONE · UI REQUIRED · S UNCHANGED
Vendor
Adobe
Product
InDesign Desktop
Versions
0 lte 19.5.5
CWE
CWE-416, Use After Free (CWE-416)
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published
2025-11-11T17:00:35.589Z
Updated
2025-11-11T17:00:35.589Z

AI Summary Analysis

Risk verdict

Why this matters

Most likely attack path

Who is most exposed

Detection ideas

  • Watch for InDesign crashes or memory-dump indicators following file opens.
  • Look for heap-corruption signals in crash reports or telemetry.
  • Monitor for suspicious file attachments or payloads delivered via email/downloads.
  • Endpoint alerts for unusual InDesign process behaviour or post-open activity.
  • SIEM detections of atypical user-initiated file handling or privilege-escalation traces after opening documents.

Mitigation and prioritisation

  • Apply the vendor patch/updates addressing the Use After Free issue (referenced advisory APSB25-106).
  • Enforce least privilege and run affected software under standard user accounts; disable or sandbox handling of untrusted files.
  • Enable application control, EDR detections, and memory-corruption related telemetry.
  • Plan patching within the next cycle; validate in staging before broad rollout.
  • No KEV or EPSS data provided; treat as priority 2; escalate to priority 1 if KEV is confirmed or EPSS ≥ 0.5.

Support Our Work

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

AI APIs OSINT driven New features