CVE-2023-25862: Adobe Illustrator Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Mar 22, 2023
·Updated
Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Adobe Illustrator<=26.5.2
Adobe Illustrator>=27.0.0<27.3.1
Event History
Mar 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25862.
2
What is the severity of CVE-2023-25862?
The severity of CVE-2023-25862 is medium with a severity value of 5.5.
3
Which versions of Adobe Illustrator are affected by CVE-2023-25862?
Adobe Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by CVE-2023-25862.
4
What is the impact of CVE-2023-25862?
CVE-2023-25862 could lead to the disclosure of sensitive memory and bypass mitigations such as ASLR.
5
Is user interaction required to exploit CVE-2023-25862?
Yes, exploitation of CVE-2023-25862 requires user interaction.