CVE-2025-24448
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 11, 2025
CWE ID 125
Summary
CVE-2025-24448 is a newly disclosed vulnerability affecting Adobe Illustrator versions 29.2.1 and 28.7.4, and possibly older releases. This issue represents an out-of-bounds read vulnerability, which means that memory beyond the allocated boundary may be accessed. Such an event could lead to the disclosure of sensitive data. Malicious actors could potentially exploit this flaw to bypass Address Space Layout Randomization (ASLR) protections, increasing the risk of successful attacks. To exploit this vulnerability, a user must open a specially crafted file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Illustrator
Affected Vendors
- Adobe