CVE-2022-30637: Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-30637?
CVE-2022-30637 is an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution.
How does CVE-2022-30637 impact Adobe Illustrator?
CVE-2022-30637 could result in arbitrary code execution in the context of the current user when a victim opens a malicious file.
Which versions of Adobe Illustrator are affected by CVE-2022-30637?
Adobe Illustrator versions 26.0.2 and earlier, as well as version 25.4.5 and earlier, are affected by CVE-2022-30637.
What is the severity of CVE-2022-30637?
CVE-2022-30637 has a severity score of 7.8 (High).
How can I fix CVE-2022-30637?
To fix CVE-2022-30637, upgrade to a version of Adobe Illustrator that is not affected by the vulnerability.