Headline
CVE-2021-44700: Adobe Security Bulletin
Adobe Illustrator versions 25.4.2 (and earlier) and 26.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Security Updates Available for Adobe Illustrator | APSB22-02
Bulletin ID
Date Published
Priority
ASPB22-02
January 11, 2022
3
Summary
Adobe has released an update for Adobe Illustrator 2021. This update resolves an important and a moderate vulnerability that could lead to privilege escalation.
Affected Versions
Product
Version
Platform
Illustrator 2022
26.0.1 and earlier versions
Windows and macOS
Illustrator 2021
25.4.2 and earlier versions
Windows and macOS
Solution
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app’s update mechanism. For more information, please reference this help page.
Product
Version
Platform
Priority
Availability
Illustrator 2022
26.0.2
Windows and macOS
3
Download Page
Illustrator 2021
25.4.3
Windows and macOS
3
Download Page
Vulnerability details
Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVSS vector
CVE Numbers
Out-of-bounds Read (CWE-125)
Privilege escalation
Moderate
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVE-2021-43752
Out-of-bounds Read (CWE-125)
Privilege escalation
Important
4.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVE-2021-44700
Acknowledgments
Adobe would like to thank the following researcher for reporting these issues and for working with Adobe to help protect our customers:
- Mat Powell of Trend Micro Zero Day Initiative --CVE-2021-43752, CVE-2021-44700
For more information, visit https://helpx.adobe.com/security.html, or email [email protected]