Description
Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Adobe / Illustrator0 – 30.1
- Adobe / Illustrator29.0 – 29.8.5
- Adobe / Illustrator Desktop 20250 – 29.8.4
- Adobe / Illustrator Desktop 202529.8.5 – 29.8.5
- Adobe / Illustrator Desktop 20260 – 30.1
- Adobe / Illustrator Desktop 202630.2 – 30.2
References
Updated 39m ago · 8 sources