Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. (CVSS:4.3) (Last Update:2022-06-24) Latest security vulnerabilities (Bypass) (CVSS score >= 4)
Enhancing Vulnerability Prioritization: Data-Driven Exploit Predictions With Community Driven Insights
In this paper, the authors present the efforts behind building a Special Interest Group (SIG) that seeks to develop a completely data-driven exploit scoring system