CVE-2023-26426: Adobe Illustrator (Beta) has a UAF vulnerability when parsing SVG files Arbitrary code execution
Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Illustrator vulnerability?
The vulnerability ID is CVE-2023-26426.
What is the severity level of CVE-2023-26426?
The severity level of CVE-2023-26426 is high with a score of 7.8.
Which versions of Illustrator are affected by CVE-2023-26426?
Illustrator version 26.5.2 and earlier, as well as version 27.2.0 and earlier, are affected by CVE-2023-26426.
What is the impact of CVE-2023-26426?
CVE-2023-26426 could result in arbitrary code execution in the context of the current user.
How can CVE-2023-26426 be exploited?
Exploitation of CVE-2023-26426 requires user interaction, where a victim must open a malicious file.
How can I check if my version of Illustrator is affected by CVE-2023-26426?
You can check if your version of Illustrator is affected by CVE-2023-26426 by referring to the software version mentioned in the vulnerability description.
Is there a fix available for CVE-2023-26426?
Yes, Adobe has provided a fix for CVE-2023-26426. Please refer to the referenced link for more information.