Executive brief
Adobe Illustrator, a professional graphics design tool used to create and edit digital artwork, contains an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a specially crafted malicious file. An attacker could exploit this to gain full control of a designer's computer, compromising sensitive artwork, client data, and intellectual property. The vulnerability affects versions 29.8.4 and 30.1 and earlier.
Technical details
The vulnerability is an out-of-bounds write flaw in Adobe Illustrator that permits arbitrary code execution with the privileges of the current user. The attack requires user interaction; specifically, a victim must open a malicious file (likely a crafted Illustrator project or document). No authentication is required and the attack vector is local, delivered via file handling. A successful exploit grants the attacker code execution in the context of the logged-in user, potentially allowing data theft, ransomware deployment, or lateral movement within a compromised system.
Affected products
- Adobe Illustrator 29.8.4, 30.1 and earlier
Timeline
- 2026-03-10: disclosed