Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7742 | Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. The problem extends to any type of critical resource that the application trusts. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 01 Apr 2025 05:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe illustrator Apple Apple macos Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:adobe:illustrator:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Adobe
Adobe illustrator Apple Apple macos Microsoft Microsoft windows |
Wed, 12 Mar 2025 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Mar 2025 03:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. The problem extends to any type of critical resource that the application trusts. | |
| Title | Illustrator | Untrusted Search Path (CWE-426) | |
| Weaknesses | CWE-426 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-03-11T18:31:11.430Z
Reserved: 2025-02-19T22:28:19.017Z
Link: CVE-2025-27167
Updated: 2025-03-11T18:28:43.665Z
Status : Analyzed
Published: 2025-03-11T18:15:34.730
Modified: 2025-03-31T20:06:44.963
Link: CVE-2025-27167
No data.
OpenCVE Enrichment
No data.
EUVD