Insecure Library Loading in Adobe Illustrator by Adobe
CVE-2019-7962

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
14 November 2019

Summary

Adobe Illustrator CC versions 23.1 and earlier are vulnerable to an insecure library loading issue which can be exploited through DLL hijacking. This flaw allows attackers to potentially escalate privileges by tricking the application into loading malicious libraries. By successfully executing this exploit, unauthorized users could gain elevated rights within the system, posing significant security risks. Users are advised to update to the latest version to mitigate this vulnerability.

Affected Version(s)

Adobe Illustrator CC 23.1 and earlier versions

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.