Impact
A flaw in Adobe Illustrator allows an out-of-bounds write that can lead to arbitrary code execution in the context of the current user. The vulnerability requires the user to open a crafted file; no remote trigger is necessary, so user interaction is the gating factor.
Affected Systems
Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are affected. The vulnerability is linked to these specific product releases by Adobe.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact, while the EPSS score of less than 1% suggests that the likelihood of widespread exploitation is low at present. The flaw is not listed in the CISA KEV catalog. Because exploitation demands that a victim opens a malicious file, the attack vector is local and relies on user action, making social engineering a key component of a potential attack.
OpenCVE Enrichment