Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2024-52989
7.8HIGH
Summary
Adobe Animate versions 23.0.8, 24.0.5 and earlier are susceptible to an Integer Underflow (Wrap or Wraparound) vulnerability. This flaw could potentially allow an attacker to execute arbitrary code with the privileges of the current user. The successful exploitation of this vulnerability requires that a user interacts with the system by opening a specially crafted malicious file. Therefore, caution should be exercised when handling unknown or suspicious files in Adobe Animate to mitigate the associated risks.
Affected Version(s)
Animate 0 <= 24.0.5
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published