First published: Wed Sep 08 2021(Updated: )
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Illustrator | <=25.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21103 is a memory corruption vulnerability in Adobe Illustrator version 25.2 and earlier.
CVE-2021-21103 allows an unauthenticated attacker to disclose sensitive memory information in the context of the current user by exploiting a specially crafted file in Adobe Illustrator.
CVE-2021-21103 has a severity level of 8.8 (Critical).
No, Microsoft Windows is not affected by CVE-2021-21103.
To fix CVE-2021-21103, update your Adobe Illustrator to version 25.3 or later, as advised in Adobe's security advisory (APSB21-24).