Severity
10.0CRITICAL
EPSS
13.9%
top 5.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 14

Description

Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDadobe/illustrator13 versions+12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di2022-05-17
CVEList
CVE-2012-2024: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di2012-05-09

📋Vendor Advisories

2
CISA
Microsoft Internet Explorer Use-After-Free Vulnerability2024-07-23
CISA
PHP-CGI OS Command Injection Vulnerability2024-06-12

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft fixes Linux boot issues on dual-boot Windows systems2025-05-14