Impact
The identified special elements used in an OS command, classified as CWE-78, allow an attacker to inject arbitrary operating system commands through a malicious file processed by Adobe Animate. If a user opens such a file, the application may execute the injected commands with the privileges of the current user, potentially enabling full system compromise.
Affected Systems
The vulnerability targets Adobe Animate 2023 and 2024 releases. Systems running these versions, irrespective of platform, are susceptible. No further product details are presently disclosed.
Risk and Exploitability
With a CVSS score of 7.7, the vulnerability poses a high risk for users who interact with malicious files. Its EPSS score is below 1% and it is not listed in the CISA KEV catalog, indicating limited observed exploitation. The change in scope allows execution in the context of the current user, so based on the description, it is inferred that a targeted social engineering or phishing campaign that convinces a user to open a crafted file could lead to remote code execution. The CVE description does not specify supported operating systems; however, any platform where Adobe Animate executes OS commands could be impacted.
OpenCVE Enrichment