CVE-2020-9727: Adobe Indesign

High severity, CVSS 7.8. EPSS: 3.1% chance of exploitation in the next 30 days.

A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

Affected products

  • Adobe Indesign: up to and including 15.1.1

Published 2020-09-10. Last modified 2026-06-17.