CVE-2022-23188: Adobe Illustrator Buffer Overflow could lead to Arbitrary code execution
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted malicious file in Illustrator.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-23188?
CVE-2022-23188 is a buffer overflow vulnerability in Adobe Illustrator versions 25.4.3 and 26.0.2.
How does CVE-2022-23188 affect Adobe Illustrator?
CVE-2022-23188 affects Adobe Illustrator versions 25.4.3 and 26.0.2 by allowing arbitrary code execution through a crafted malicious file.
What is the severity of CVE-2022-23188?
The severity of CVE-2022-23188 is rated as high with a CVSS score of 7.8.
How can I fix CVE-2022-23188?
To fix CVE-2022-23188, update Adobe Illustrator to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-23188?
More information about CVE-2022-23188 can be found on the Adobe Security Bulletin APSB22-07.