Impact
Adobe Animate 2023 and 2024 contain an Improper Control of Generation of Code vulnerability, classified as CWE‑94, that allows an attacker to inject and execute arbitrary code in the context of the current user. The flaw is triggered by opening a specially crafted file, enabling a low‑privileged adversary to run code with the victim’s permissions, thereby compromising confidentiality, integrity, and availability of the user’s system.
Affected Systems
The affected products are Adobe Animate 2023 and Adobe Animate 2024. These versions are vulnerable if the user is running any of the stated releases and opens a malicious file.
Risk and Exploitability
The vulnerability has a CVSS score of 8.2, indicating a high impact. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires that the victim interactively opens a malicious file, but once triggered it allows arbitrary code execution. The attack vector is user‑initiated file opening, and no elevated privileges are required for the attacker.
OpenCVE Enrichment