CVE-2025-61820
7.8Adobe · Illustrator
Adobe Illustrator versions 28.7.10, 29.8.2 and earlier are vulnerable to a heap-based buffer overflow that may allow arbitrary code execution when a victim opens a malicious file.
Executive summary
Adobe Illustrator is affected by a heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a user system via a malicious file.
Vulnerability
This is a heap-based buffer overflow (CWE-122) triggered when the application processes a crafted file. The attack requires user interaction, as a victim must be enticed to open the malicious file, at which point the code executes in the context of the current user.
Business impact
Successful exploitation of this vulnerability can lead to arbitrary code execution, potentially resulting in full system compromise, data theft, or the installation of persistent malware. Given the CVSS score of 7.8, this is classified as a high-severity risk that could significantly impact organizational workstation security and internal data confidentiality.
Remediation
Immediate Action: Update Adobe Illustrator to the latest version as specified in the Adobe security bulletin APSB25-109.
Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or unauthorized process spawning originating from the Adobe Illustrator executable.
Compensating Controls: Ensure that users are instructed not to open unexpected or untrusted files, and utilize endpoint protection software capable of detecting malicious file structures or behavioral anomalies.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize patching Adobe Illustrator across all workstations to address this heap-based buffer overflow. Since exploitation requires user interaction via a malicious file, security teams should also reinforce user awareness regarding the risks of opening unexpected documents from untrusted sources. Applying the vendor-provided update is the only definitive way to eliminate this risk.