CVE-2020-3711 is a memory corruption vulnerability affecting Adobe Illustrator CC versions 24.0 and earlier, impacting both Windows and macOS platforms. This high-severity flaw, rated 7.8 CVSS, can be exploited through user interaction (e.g., opening a malicious file) and could lead to arbitrary code execution with high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community. It is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.0.2CPE matchmatch criteria | cpe:2.3:a:adobe:illustrator_cc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.