CVE-2022-30642: Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-30642?
CVE-2022-30642 is an out-of-bounds write vulnerability in Adobe Illustrator versions 26.0.2 and earlier that could lead to arbitrary code execution.
How can the CVE-2022-30642 vulnerability be exploited?
To exploit the CVE-2022-30642 vulnerability, a victim must open a malicious file that triggers the out-of-bounds write.
What is the severity of CVE-2022-30642?
CVE-2022-30642 has a severity rating of 7.8 (high).
Which versions of Adobe Illustrator are affected by CVE-2022-30642?
Adobe Illustrator versions 26.0.2 and earlier, as well as 25.4.5 and earlier, are affected by CVE-2022-30642.
Is Apple macOS or Microsoft Windows vulnerable to CVE-2022-30642?
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2022-30642.
How can I fix CVE-2022-30642?
To fix CVE-2022-30642, update Adobe Illustrator to version 26.0.3 or later.
Where can I find more information about CVE-2022-30642?
More information about CVE-2022-30642 can be found on the Adobe Security Bulletin APSB22-26.
What is the Common Weakness Enumeration (CWE) for CVE-2022-30642?
The Common Weakness Enumeration (CWE) for CVE-2022-30642 is CWE-787 (Out-of-bounds Write).