CVE-2024-47455: Illustrator | Out-of-bounds Read (CWE-125)
Published Nov 12, 2024
·Updated
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
All of the following
Adobe Illustrator<28.7.2
Any of the following
macOS
Microsoft Windows
Event History
Nov 12, 2024
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47455?
CVE-2024-47455 has a high severity rating due to its potential to disclose sensitive memory information.
2
How do I fix CVE-2024-47455?
To mitigate CVE-2024-47455, users should upgrade Adobe Illustrator to version 28.7.2 or later.
3
What type of vulnerability is CVE-2024-47455?
CVE-2024-47455 is classified as an out-of-bounds read vulnerability.
4
Is user interaction required for exploiting CVE-2024-47455?
Yes, exploitation of CVE-2024-47455 requires user interaction.
5
Which versions of Adobe Illustrator are affected by CVE-2024-47455?
Adobe Illustrator versions 28.7.1 and earlier are affected by CVE-2024-47455.