CVE-2020-3714 describes a memory corruption vulnerability in Adobe Illustrator CC versions 24.0 and earlier, affecting both Windows and macOS installations. This high-severity flaw (CVSS 7.8) can be exploited through user interaction (e.g., opening a malicious file) and could lead to arbitrary code execution with high impact on confidentiality, integrity, and availability. While no public exploits or KEV entries exist, the vulnerability has garnered some community discussion and media coverage, indicating awareness. Organizations should prioritize patching to mitigate the risk of successful exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.0.2CPE matchmatch criteria | cpe:2.3:a:adobe:illustrator_cc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.