First published: Tue Mar 11 2025(Updated: )
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Illustrator 2024 | <28.7.4 | |
All of | ||
Any of | ||
Adobe Illustrator 2024 | >=28.0<28.7.5 | |
Adobe Illustrator 2024 | >=29.0<29.3 | |
Any of | ||
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27169 is considered a critical vulnerability due to the potential for arbitrary code execution.
To mitigate CVE-2025-27169, update Adobe Illustrator to version 29.2.2 or later as instructed by Adobe.
CVE-2025-27169 affects Adobe Illustrator versions 29.2.1, 28.7.4, and earlier.
CVE-2025-27169 could allow an attacker to execute arbitrary code on the affected system after the victim opens a malicious file.
Yes, exploitation of CVE-2025-27169 requires user interaction, specifically the opening of a malicious file.