Adobe Illustrator
cpe:2.3:a:adobe:illustrator:*:*:*:*:*:*:*
- <= 29.5.1
- <= 28.7.6
A vulnerability allowing arbitrary code execution has been identified in Adobe Illustrator versions 28.7.6, 29.5.1 and earlier. This issue arises from an integer overflow or wraparound vulnerability that could be exploited if a victim opens a malicious file. The execution of the arbitrary code occurs in the context of the current user.
Exploitation of this vulnerability could result in arbitrary code execution on the affected system, with the executed code running under the privileges of the user who opened the malicious file.
Users are advised to update Adobe Illustrator to version 29.6 or above for the 2025 release, or to version 28.7.8 or above for the 2024 release. The update can be downloaded from the Adobe Download Page or through the Creative Cloud desktop app's update mechanism.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.