Impact
Adobe Illustrator versions 29.8.4, 30.1 and earlier contain an out‑of‑bounds read flaw that could expose data stored in memory. An attacker who tricks a user into opening a crafted AI file can read arbitrary memory within the Illustrator process. This flaw may reveal sensitive information such as credentials or proprietary data, but does not provide code execution or system compromise.
Affected Systems
All versions of Adobe Illustrator up to and including 29.8.4 and 30.1, running on Microsoft Windows, are affected. The flaw does not impact other Adobe products or non‑Windows platforms, as the security advisory references Windows environments in its impact statement.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity, and the EPSS score of less than 1% suggests that exploitation is unlikely at present. Because the vulnerability requires the victim to open a malicious file, successful exploitation depends on user interaction and the presence of a crafted AI file. The issue is not listed in the CISA KEV catalog, implying no evidence of widespread exploitation so far. Nonetheless, the memory exposure could leak confidential information that could be used in further attacks.
OpenCVE Enrichment