Impact
This vulnerability is a NULL Pointer Dereference identified as CWE-476 that can cause Adobe Illustrator to crash when processing a specially crafted file. A crash results in a denial‑of‑service within the application, preventing the user from continuing work and potentially disrupting dependent workflows. The flaw does not provide code execution or privilege escalation but can be leveraged to interrupt productivity.
Affected Systems
The issue affects Adobe Illustrator versions 29.8.3, 30.0, and all earlier releases on Windows and macOS platforms. No specific operating‑system version is required beyond those where Illustrator runs. The vulnerability is tied to the Adobe Illustrator application, not the underlying OS.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. EPSS shows a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker must provide a malicious file to a user who then opens it, so the vector relies on user interaction. While the risk of spontaneous exploitation is low, the potential for targeted attacks in environments where users frequently handle unknown files heightens concern.
OpenCVE Enrichment