Impact
Adobe Animate is vulnerable to an incorrect authorization flaw that can allow an attacker to execute arbitrary code with the privileges of the user currently logged on. The vulnerability changes the scope of the affected system, meaning that any code running inside the application could potentially be used to conduct further attacks. The description notes that exploitability relies on conditions beyond an attacker’s control and that no user interaction is required, implying that while the window of opportunity may be limited, the potential impact is severe if those conditions are met.
Affected Systems
The affected products are Adobe Animate 2023 and Adobe Animate 2024, as identified by the CNA. No explicit sub‑version information is available, so all builds of these product releases should be treated as affected until a patch is applied.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, and the EPSS score of < 1% suggests a very low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Because exploitation does not require user interaction but depends on conditions beyond the attacker’s control, the practical risk is somewhat mitigated, yet the potential for local privilege escalation or remote code execution remains significant.
OpenCVE Enrichment