Untrusted Search Path Vulnerability in Adobe Illustrator
CVE-2025-27167
7.8HIGH
Summary
Adobe Illustrator is susceptible to an untrusted search path vulnerability that could be exploited by attackers to execute unauthorized programs, gain access to sensitive data files, or tamper with application settings. This flaw arises when the application relies on a defined search path to locate essential resources. An attacker may manipulate this search path, directing it towards malicious software, which consequently gets executed by Illustrator. The scope of this issue encompasses any critical resource that the application is designed to trust, posing a significant threat to users' data integrity and security.
Affected Version(s)
Illustrator 0 <= 28.7.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved