CVE-2020-24412: Adobe Illustrator Memory Corruption Vulnerability
Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24412?
CVE-2020-24412 has been identified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2020-24412?
To resolve CVE-2020-24412, update Adobe Illustrator to version 24.2 or later.
What causes the CVE-2020-24412 vulnerability?
CVE-2020-24412 is caused by a memory corruption issue when Adobe Illustrator processes a specially crafted .svg file.
Is user interaction required to exploit CVE-2020-24412?
Yes, user interaction is required to open the specially crafted SVG file to exploit CVE-2020-24412.
Which versions of Adobe Illustrator are affected by CVE-2020-24412?
Adobe Illustrator versions 24.1.2 and earlier are affected by CVE-2020-24412.