PT-2024-6230 · Adobe · Illustrator

Published

2024-09-10

·

Updated

2024-09-16

·

CVE-2024-41857

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Illustrator versions 28.6, 27.9.5 and earlier
Description The issue is related to an integer underflow vulnerability. Exploitation of this issue could result in arbitrary code execution in the context of the current user. This requires user interaction, where a victim must open a malicious file.
Recommendations For Adobe Illustrator versions 28.6, 27.9.5 and earlier, avoid opening malicious files until a patch is available. As a temporary workaround, consider restricting access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Underflow

Weakness Enumeration

Related Identifiers

BDU:2024-07177
CVE-2024-41857

Affected Products

Illustrator