Impact
Adobe Animate suffers from a weakness in its authorization logic that allows an attacker to run arbitrary code under the current user’s permission level. A malicious file crafted by the attacker, when opened in Animate, triggers the exploit and bypasses intended access controls, enabling code execution as the victim. This is a classic CWE‑863 flaw where insufficient checks against user privileges are performed, undermining the application’s security guarantees.
Affected Systems
The flaw impacts Adobe Animate versions 2023 and 2024 released by Adobe Systems. Any installation of those major releases is potentially affected; no specific sub‑version details are provided, so a broad range of installations could be vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating high severity, but its EPSS score is below 1%, suggesting a low probability of exploitation in the wild. It is not currently listed in the CISA KEV catalog, and exploitation requires user interaction—specifically, a victim must open a malicious file. Once the file is opened, the scope changes, giving the attacker the ability to execute code with the victim’s rights, which can compromise system integrity and confidentiality.
OpenCVE Enrichment