Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2024-52989

7.8HIGH

Key Information:

Vendor
Adobe
Status
Vendor
CVE Published:
10 December 2024

Summary

Adobe Animate versions 23.0.8, 24.0.5 and earlier are susceptible to an Integer Underflow (Wrap or Wraparound) vulnerability. This flaw could potentially allow an attacker to execute arbitrary code with the privileges of the current user. The successful exploitation of this vulnerability requires that a user interacts with the system by opening a specially crafted malicious file. Therefore, caution should be exercised when handling unknown or suspicious files in Adobe Animate to mitigate the associated risks.

Affected Version(s)

Animate 0 <= 24.0.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.