PT-2020-4577 · Adobe · Illustrator
Published
2020-10-20
·
Updated
2021-09-14
·
CVE-2020-24415
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Illustrator versions prior to 24.1.2
Description
The issue is related to a memory corruption vulnerability that occurs when parsing a specially crafted .svg file, potentially allowing an attacker to execute arbitrary code in the context of the current user. This vulnerability requires user interaction to exploit.
Recommendations
For Adobe Illustrator version 24.1.2 and earlier, update to a version later than 24.1.2 to resolve the issue.
At the moment, there is no information about other specific mitigation measures for this vulnerability.
Fix
Buffer Overflow
Memory Corruption
Access of Memory Location After End of Buffer
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Illustrator