CVE-2022-23186: Adobe Illustrator Out-of-bounds Write could lead to Arbitrary code execution
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-23186?
CVE-2022-23186 is an out-of-bounds write vulnerability in Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) that could allow arbitrary code execution.
How does CVE-2022-23186 impact Adobe Illustrator?
CVE-2022-23186 could result in arbitrary code execution in the context of the current user if a victim opens a malicious file.
Is Apple macOS affected by CVE-2022-23186?
Apple macOS is not vulnerable to CVE-2022-23186.
Is Microsoft Windows affected by CVE-2022-23186?
Microsoft Windows is not vulnerable to CVE-2022-23186.
How can I fix CVE-2022-23186?
To fix CVE-2022-23186, update Adobe Illustrator to version 26.0.3 or later.