First published: Tue Mar 11 2025(Updated: )
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Illustrator 2024 | <29.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27170 has a high severity due to its potential to cause denial-of-service conditions in affected versions of Adobe Illustrator.
To fix CVE-2025-27170, update Adobe Illustrator to the latest version beyond 29.2.1 as recommended by the vendor.
CVE-2025-27170 affects Adobe Illustrator versions 29.2.1, 28.7.4, and earlier.
CVE-2025-27170 allows an attacker to exploit a NULL Pointer Dereference vulnerability, potentially crashing the application.
In the context of CVE-2025-27170, a NULL Pointer Dereference vulnerability occurs when the application attempts to access an object or resource that has not been properly initialized, leading to application crashes.