Description
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-01-13
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (application crash)
Action: Update Illustrator
AI Analysis

Impact

This vulnerability is a NULL Pointer Dereference identified as CWE-476 that can cause Adobe Illustrator to crash when processing a specially crafted file. A crash results in a denial‑of‑service within the application, preventing the user from continuing work and potentially disrupting dependent workflows. The flaw does not provide code execution or privilege escalation but can be leveraged to interrupt productivity.

Affected Systems

The issue affects Adobe Illustrator versions 29.8.3, 30.0, and all earlier releases on Windows and macOS platforms. No specific operating‑system version is required beyond those where Illustrator runs. The vulnerability is tied to the Adobe Illustrator application, not the underlying OS.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity. EPSS shows a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker must provide a malicious file to a user who then opens it, so the vector relies on user interaction. While the risk of spontaneous exploitation is low, the potential for targeted attacks in environments where users frequently handle unknown files heightens concern.

Generated by OpenCVE AI on April 18, 2026 at 06:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Illustrator update that resolves the NULL pointer dereference issue.
  • Avoid opening unknown or suspicious files; verify source authenticity before loading into Illustrator.
  • When possible, run Illustrator in a sandboxed or virtualized environment to contain crashes and protect other work.

Generated by OpenCVE AI on April 18, 2026 at 06:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 14 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:illustrator:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:illustrator:30.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Microsoft
Microsoft windows

Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe illustrator
Vendors & Products Adobe
Adobe illustrator

Tue, 13 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 19:00:00 +0000

Type Values Removed Values Added
Description Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Illustrator | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-01-13T19:02:39.353Z

Reserved: 2025-12-12T22:01:18.190Z

Link: CVE-2026-21288

cve-icon Vulnrichment

Updated: 2026-01-13T19:02:31.815Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T19:16:26.173

Modified: 2026-01-14T19:29:14.490

Link: CVE-2026-21288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T06:45:23Z

Weaknesses