CVE-2021-21104: Adobe Illustrator memory corruption vulnerability could lead to remote code execution
Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21104?
CVE-2021-21104 is a memory corruption vulnerability in Adobe Illustrator version 25.2 and earlier, which can be exploited by a specially crafted file to achieve remote code execution.
How severe is CVE-2021-21104?
CVE-2021-21104 has a severity rating of 8.8, which is considered critical.
How does CVE-2021-21104 impact Adobe Illustrator?
CVE-2021-21104 allows an unauthenticated attacker to remotely execute code in the context of the current user by exploiting a memory corruption vulnerability in Adobe Illustrator.
Is Microsoft Windows affected by CVE-2021-21104?
No, Microsoft Windows is not affected by CVE-2021-21104.
How can I mitigate the risk of CVE-2021-21104?
To mitigate the risk of CVE-2021-21104, it is recommended to update Adobe Illustrator to version 25.3 or later, as provided by the vendor.