Impact
Illustrator is vulnerable to an untrusted search path flaw (CWE-426) that allows a crafted file to execute arbitrary code in the context of the user who opens it. The flaw changes scope, giving the attacker the same privileges as the target user and enabling full control over the system. If exploited, malicious code could run with the victim’s user rights, potentially leading to data theft, system compromise, or further lateral movement.
Affected Systems
Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are affected. No information is provided regarding the availability of patches or updates in this data set.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. The EPSS score of < 1% indicates a low probability of exploitation at this time, and the issue is not currently listed in CISA’s KEV catalog. The likely attack vector requires the victim to open a malicious Illustrator file, so user interaction is a prerequisite. Because the effect is code execution under the current user’s privileges, the impact is serious if a user does fall for the lure.
OpenCVE Enrichment