CVE-2022-30649: Adobe Illustrator Out-of-bounds Write could lead to Arbitrary code execution
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-30649?
CVE-2022-30649 is an out-of-bounds write vulnerability in Adobe Illustrator versions 26.0.2 and earlier, and 25.4.5 and earlier.
How severe is CVE-2022-30649?
CVE-2022-30649 has a severity rating of 7.8, which is considered high.
How does CVE-2022-30649 affect Adobe Illustrator?
CVE-2022-30649 can result in arbitrary code execution in the context of the current user if a victim opens a malicious file.
What versions of Adobe Illustrator are affected by CVE-2022-30649?
Adobe Illustrator versions 26.0.2 and earlier, as well as 25.4.5 and earlier, are affected by CVE-2022-30649.
Is Apple macOS or Microsoft Windows affected by CVE-2022-30649?
No, Apple macOS and Microsoft Windows are not affected by CVE-2022-30649.
How can I find more information about CVE-2022-30649?
You can find more information about CVE-2022-30649 at the following reference: https://helpx.adobe.com/security/products/illustrator/apsb22-26.html