Impact
Adobe Illustrator’s vulnerability arises from improper validation of file input. An attacker can craft a malicious file that, when a user opens it, causes arbitrary code execution in the user’s context, potentially granting the attacker elevated privileges or full control over the victim’s account or session. This weakness, identified as CWE‑20, alters the scope of the affected system when exploited.
Affected Systems
The flaw affects Adobe Illustrator Desktop versions 2025 and 2026. No specific patch version numbers are listed in the advisory, but the issue applies to all installations of these releases that have not been updated with the later security release.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability has not yet been listed in the CISA KEV catalog. Exploitation requires user interaction – the victim must open the malicious file. Once the file is opened, the attacker can run arbitrary code in the context of the current user, potentially gaining elevated access or control over the victim’s account or session. The change in scope highlights the importance of applying the update as soon as it is available.
OpenCVE Enrichment