CVE-2025-49563

7.8

Adobe · Illustrator

Adobe Illustrator is affected by an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution through a maliciously crafted file.

Executive summary

Adobe Illustrator versions 29.6.1 and earlier contain an out-of-bounds write vulnerability that exposes users to arbitrary code execution if they open a malicious file.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) flaw that triggers when the application processes a specially crafted file. Successful exploitation requires user interaction, specifically requiring the victim to open the malicious file within the application.

Business impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, potentially leading to a complete compromise of the workstation. Given the CVSS score of 7.8, this vulnerability poses a significant risk to organizational data integrity and system security, as an attacker could gain control over the user session and access sensitive project files or credentials.

Remediation

Immediate Action: Update Adobe Illustrator to the latest version provided by the vendor in the security advisory APSB25-74.

Proactive Monitoring: Monitor endpoint activity for unexpected child processes spawned by the Illustrator application.

Compensating Controls: Advise users to avoid opening Illustrator files from untrusted or unknown sources to mitigate the risk of triggering the exploit.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize patching Adobe Illustrator across all managed workstations to address this high-severity vulnerability. Given that the exploit is triggered by opening a malicious file, end-user awareness regarding file handling is a necessary supplement to the mandatory software update.

More Adobe CVEs

Sources