Impact
Adobe Animate contains a path‑traversal flaw (CWE‑22) that allows a crafted animation file to reference directories outside the intended sandbox. When the victim opens the malicious file, the software can read sensitive files or execute code with the privileges of the current user. Because the vulnerability is a scope‑changing flaw, it may elevate privileges beyond the current user, but the advisory does not specify the exact level of privilege escalation, leaving uncertainty.
Affected Systems
Adobe Animate desktop versions 2023 and 2024 are affected. All builds released during those years are considered vulnerable unless a later update explicitly removes the flaw.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is scope‑changing, an attacker might be able to achieve privilege escalation beyond the current user; however, the extent of this elevation is not detailed in the advisory. Effective exploitation still requires a user to open a malicious animation file, after which the software could traverse directories or execute code as that user.
OpenCVE Enrichment