CVE-2020-24421: Adobe Indesign

Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue.

Affected products

  • Adobe Indesign: up to and including 15.1.2

Published 2020-10-21. Last modified 2026-06-17.