CVE-2025-27170: Illustrator | NULL Pointer Dereference (CWE-476)
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Illustratorto a version that resolves this vulnerability.Fixed in 29.2.1 - Upgrade
Upgrade
Illustratorto a version that resolves this vulnerability.Fixed in 28.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27170?
CVE-2025-27170 has a high severity due to its potential to cause denial-of-service conditions in affected versions of Adobe Illustrator.
How do I fix CVE-2025-27170?
To fix CVE-2025-27170, update Adobe Illustrator to the latest version beyond 29.2.1 as recommended by the vendor.
What versions of Adobe Illustrator are affected by CVE-2025-27170?
CVE-2025-27170 affects Adobe Illustrator versions 29.2.1, 28.7.4, and earlier.
What kind of attack is possible with CVE-2025-27170?
CVE-2025-27170 allows an attacker to exploit a NULL Pointer Dereference vulnerability, potentially crashing the application.
What is a NULL Pointer Dereference vulnerability in the context of CVE-2025-27170?
In the context of CVE-2025-27170, a NULL Pointer Dereference vulnerability occurs when the application attempts to access an object or resource that has not been properly initialized, leading to application crashes.