Impact
Adobe Animate suffers from an OS Command Injection flaw caused by improper neutralization of special elements; an attacker can embed malicious commands within a file that, when opened by a user, are executed with the victim’s privileges. The vulnerability’s scope is changed, meaning that exploitation can affect the entire system if the user runs the application as an administrator. The impact is the ability to execute arbitrary code and potentially install malware or exfiltrate data.
Affected Systems
Adobe Animate versions 2023 and 2024 are affected. No other Adobe products are listed in the CNA data.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity. The EPSS score is reported as less than 1 %, showing a very low probability of exploitation in the wild, and the issue is not currently listed in the CISA KEV catalog. Because the exploit requires the victim to open a malicious file, the attack vector is user interaction; once the file is opened, the attacker gains code execution in the context of the current user. Despite the low exploitation probability, the high impact and wide availability of the affected Adobe Animate editions warrant immediate attention.
OpenCVE Enrichment