Impact
Illustrator is vulnerable to an Incorrect Authorization flaw that permits an attacker to run arbitrary code within the context of the currently logged‑in user. The vulnerability requires the victim to open a specially crafted file, after which code execution is achieved. The flaw escalates privileges, potentially granting the attacker full control of the affected system.
Affected Systems
Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are impacted by this issue. The problem resides in the file import functionality and is not limited to a specific operating system or installation set.
Risk and Exploitability
The flaw receives a CVSS score of 8.6, indicating a high severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. Over the above, the exploit needs user interaction and a crafted file; attackers often rely on social‑engineering or phishing emails to deliver the malicious document. Once executed, the code runs with the victim’s privileges, enabling full system compromise.
OpenCVE Enrichment