Adobe Animate
cpe:2.3:a:adobe:animate:*:*:*:*:*:*:*
- <= 23.0.15
- <= 24.0.13
A vulnerability allowing improper neutralization of special elements used in operating system commands has been identified in Adobe Animate. This OS command injection vulnerability could lead to arbitrary code execution within the context of the current user. The issue is present in Adobe Animate 2023 versions through 23.0.15 and in Adobe Animate 2024 versions through 24.0.13, on both Windows and macOS. Exploitation of this vulnerability requires user interaction, as a victim must open a malicious file.
Exploitation of this vulnerability could result in arbitrary code execution, allowing an attacker to execute malicious code in the context of the user running Adobe Animate.
Users are advised to update Adobe Animate to version 23.0.16 for the 2023 release or version 24.0.14 for the 2024 release. These updates are available through the Adobe Download Center. For IT administrators managing Creative Cloud applications, the Admin Console can be used to deploy these updates to end users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.