CVE-2025-27169: Illustrator | Out-of-bounds Write (CWE-787)
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Illustratorto a version that resolves this vulnerability.Fixed in 29.2.1 - Upgrade
Upgrade
Adobe Illustratorto a version that resolves this vulnerability.Fixed in 28.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27169?
CVE-2025-27169 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2025-27169?
To mitigate CVE-2025-27169, update Adobe Illustrator to version 29.2.2 or later as instructed by Adobe.
What versions of Adobe Illustrator are affected by CVE-2025-27169?
CVE-2025-27169 affects Adobe Illustrator versions 29.2.1, 28.7.4, and earlier.
What type of attack does CVE-2025-27169 enable?
CVE-2025-27169 could allow an attacker to execute arbitrary code on the affected system after the victim opens a malicious file.
Is user interaction required for exploiting CVE-2025-27169?
Yes, exploitation of CVE-2025-27169 requires user interaction, specifically the opening of a malicious file.