Heap-based Buffer Overflow in Adobe Illustrator
CVE-2025-30330

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 May 2025

What is CVE-2025-30330?

Adobe Illustrator versions 29.3, 28.7.5, and earlier versions suffer from a heap-based buffer overflow vulnerability that may lead to arbitrary code execution in the context of the current user. For exploitation to occur, user interaction is necessary as the victim must open a specially crafted malicious file. This flaw poses a significant risk if users are targeted with deceptive files capable of triggering the vulnerability.

Affected Version(s)

Illustrator 0 <= 28.7.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30330 : Heap-based Buffer Overflow in Adobe Illustrator