Impact
Animate is affected by an untrusted search path vulnerability that allows an attacker to execute arbitrary code in the context of the current user. The flaw occurs when the application searches for executable files in a non‑secured directory, enabling a malicious file to be invoked during normal operation. Because the vulnerability changes scope, the attacker could also gain elevated privileges on the system.
Affected Systems
Adobe Animate 2023 and Adobe Animate 2024 are impacted. No specific sub‑versions are listed beyond these product releases.
Risk and Exploitability
With a CVSS score of 7.9, the vulnerability presents high severity, but its EPSS score of less than 1% indicates that it is currently unlikely to be widely exploited, and it is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious file. Once executed, code runs under the user's privileges and may elevate privileges due to the scope change. The attack path relies on untrusted directories in the execution search path, making exploitation possible if such directories are writable or accessible.
OpenCVE Enrichment