CVE-2025-21160
Published: 11 February 2025
Description
Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Security Summary
CVE-2025-21160 is an Integer Underflow (Wrap or Wraparound) vulnerability, classified as CWE-191, affecting Adobe Illustrator versions 29.1, 28.7.3, and earlier. Published on 2025-02-11, the flaw could result in arbitrary code execution in the context of the current user.
Exploitation requires user interaction, as a victim must open a malicious file. The CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attacker with no privileges needed can exploit it with low attack complexity, leading to high impacts on confidentiality, integrity, and availability within the unchanged user scope.
Adobe's security advisory at https://helpx.adobe.com/security/products/illustrator/apsb25-11.html provides details on the issue.
Details
- CWE(s)