PT-2024-9510 · Adobe · Animate

Published

2024-12-10

·

Updated

2024-12-18

·

CVE-2024-52982

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Animate versions 23.0.8, 24.0.5 and earlier
Description: The issue is related to insufficient input validation, which could allow an attacker to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction, specifically that a victim must open a malicious file.
Recommendations: For versions 23.0.8 and earlier, and 24.0.5 and earlier, avoid opening files from untrusted sources to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of files that may trigger the vulnerability until a patch is available. For all affected versions, ensure that only trusted files are opened to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-11210
CVE-2024-52982

Affected Products

Animate