First published: Tue Feb 11 2025(Updated: )
Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Illustrator CC | <29.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-21160 has a high severity due to its potential for arbitrary code execution.
To fix CVE-2025-21160, update Adobe Illustrator to version 29.2 or higher.
CVE-2025-21160 affects Adobe Illustrator versions 29.1, 28.7.3, and earlier.
CVE-2025-21160 is categorized as an Integer Underflow vulnerability.
Yes, exploitation of CVE-2025-21160 requires the victim to open a malicious file.