CVE-2022-30669: Adobe Illustrator Out-of-bounds Read Vulnerability could lead to Memory Leak
Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-30669?
CVE-2022-30669 is an out-of-bounds read vulnerability in Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) that could lead to disclosure of sensitive memory.
How does CVE-2022-30669 affect Adobe Illustrator?
CVE-2022-30669 affects Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) by allowing an attacker to perform an out-of-bounds read, potentially leading to the disclosure of sensitive memory.
What can an attacker do with CVE-2022-30669?
An attacker can exploit CVE-2022-30669 to bypass mitigations such as ASLR and potentially disclose sensitive memory.
How severe is CVE-2022-30669?
CVE-2022-30669 has a severity rating of 5.5 (medium).
How can I fix CVE-2022-30669?
To fix CVE-2022-30669, users should update Adobe Illustrator to version 26.0.3 or later.