Executive brief
Adobe Illustrator is a widely used professional graphics design application. A stack-based buffer overflow vulnerability in versions 29.8.4 and 30.1 could allow attackers to execute arbitrary code on a user's computer by tricking them into opening a malicious file. Successful exploitation would grant an attacker complete control over the victim's system with the privileges of the logged-in user.
Technical details
A stack-based buffer overflow vulnerability exists in Adobe Illustrator versions 29.8.4 and earlier in the 30.x branch (30.1 and earlier). The vulnerability is triggered when processing a specially crafted file, causing a stack buffer to overflow and enabling arbitrary code execution in the context of the current user. Exploitation requires user interaction—a victim must be socially engineered to open a malicious file. No patch availability information is provided in the advisory, though the CVE number suggests this is a known and documented issue. The CVSS score of 7.8 reflects high severity due to the potential for arbitrary code execution, though the requirement for user interaction prevents a critical rating.
Affected products
- Adobe Illustrator 29.8.4 and earlier, 30.1 and earlier
Timeline
- 2026-03-10: disclosed: CVE-2026-27267 published