CVE-2024-30272: Adobe Illustrator 2024 GIF file parsing Out-Of-Bound Write remote code execution vulnerabiity
Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30272?
CVE-2024-30272 is considered a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-30272?
To fix CVE-2024-30272, update Adobe Illustrator to version 27.9.3 or later for versions below 28.4.
What versions of Illustrator are affected by CVE-2024-30272?
Illustrator versions 28.3, 27.9.2, and earlier versions are affected by CVE-2024-30272.
What are the consequences of exploiting CVE-2024-30272?
Exploiting CVE-2024-30272 could lead to arbitrary code execution with the privileges of the current user.
Does CVE-2024-30272 require user interaction to be exploited?
Yes, exploitation of CVE-2024-30272 requires user interaction, specifically opening a malicious file.