Use After Free Vulnerability in Adobe Animate by Adobe
CVE-2024-49526

7.8HIGH

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
12 November 2024

Summary

A Use After Free vulnerability has been identified in Adobe Animate versions 23.0.7, 24.0.4, and earlier. This flaw can lead to arbitrary code execution, potentially allowing an attacker to execute malicious code in the context of the current user. Successful exploitation of this vulnerability requires user interaction, as it necessitates that the victim open a specially crafted file. Users of affected versions should take necessary precautions to mitigate risks associated with this security issue.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.