CVE-2022-30640: Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-30640?
CVE-2022-30640 is an out-of-bounds write vulnerability in Adobe Illustrator versions 26.0.2 and earlier (including 25.4.5 and earlier) that could allow arbitrary code execution.
How does CVE-2022-30640 impact Adobe Illustrator?
CVE-2022-30640 could allow an attacker to execute arbitrary code in the context of the current user by exploiting the vulnerable out-of-bounds write vulnerability in Adobe Illustrator versions 26.0.2 and earlier.
What is the severity of CVE-2022-30640?
CVE-2022-30640 has a severity score of 7.8 (high).
How can I fix CVE-2022-30640?
To fix CVE-2022-30640, upgrade to a version of Adobe Illustrator that is not affected by the vulnerability. Refer to the official Adobe security advisory for more information and patch availability.
Where can I find more information about CVE-2022-30640?
You can find more information about CVE-2022-30640 in the official Adobe security advisory: https://helpx.adobe.com/security/products/illustrator/apsb22-26.html