CVE-2025-27170
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 11, 2025
Updated: Mar 31, 2025
CWE ID 476
Summary
CVE-2025-27170 is a NULL Pointer Dereference vulnerability affecting Adobe Illustrator versions 29.2.1 and 28.7.4, and possibly older releases. This issue causes the application to crash, resulting in a denial-of-service condition. An attacker can exploit this vulnerability by getting a user to open a specially crafted file. No unauthorized access or data theft occurs with this exploit; it only causes the application to stop functioning, leading to a disruption in workflow.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Illustrator
Affected Vendors
- Adobe