Impact
An out‑of‑bounds write in Adobe Illustrator allows an attacker to overwrite data structures, enabling arbitrary code execution when a victim opens a crafted file. The flaw is a classic buffer overrun (CWE‑787) that, if successfully exploited, grants the attacker the rights of the current user, potentially allowing system‑wide compromise, data theft, or installation of persistent malware. The description states that the victim must interact by opening a malicious file, so the impact is contingent on user action.
Affected Systems
The vulnerability is present in Adobe Illustrator Desktop 2025 and 2026 releases. Users with either of these versions are affected; versions prior to 2025 and any other Adobe product are not mentioned as impacted.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity, but the EPSS score is not provided, suggesting limited publicly known exploitation. The flaw requires user interaction, making it a “bad‑actor” style threat rather than an automated network exploit. Since the vulnerability is not listed in the CISA KEV catalog, it is not confirmed as currently exploited in the wild, though the high score indicates that if it were, the impact could be severe.
OpenCVE Enrichment