CVE-2025-49564

7.8

Adobe · Illustrator

Adobe Illustrator is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code if a user opens a specially crafted malicious file.

Executive summary

A critical stack-based buffer overflow in Adobe Illustrator allows for arbitrary code execution, requiring user interaction to trigger the vulnerability.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) that occurs when processing malformed files. An unauthenticated attacker can achieve arbitrary code execution in the context of the current user, provided the victim is enticed to open a malicious file.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected user's workstation. Given the CVSS score of 7.8, this represents a high-severity risk that could result in unauthorized data access, the installation of persistent malware, or lateral movement within the corporate network.

Remediation

Immediate Action: Update Adobe Illustrator to the latest version as specified in the vendor security advisory APSB25-74.

Proactive Monitoring: Monitor endpoint security logs for abnormal process execution patterns associated with Illustrator, such as unexpected child processes spawned by the application.

Compensating Controls: Ensure that users are instructed to exercise caution when opening files from untrusted sources and utilize endpoint protection software to detect and block malicious file execution.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability presents a severe risk to organizational security due to the potential for arbitrary code execution. Organizations should prioritize the deployment of the vendor-supplied security update across all affected systems immediately to eliminate the underlying stack-based buffer overflow.

More Adobe CVEs

Sources