Executive brief
Adobe Animate, a professional animation and multimedia authoring tool, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands and access or delete sensitive data with the same permissions as the logged-in user.
Technical details
An OS Command Injection vulnerability (CWE-78) exists in Adobe Animate due to improper neutralization of special elements used in operating system commands. The vulnerability is triggered when the application processes a maliciously crafted file, requiring user interaction (UI:R). Successful exploitation allows for arbitrary code execution in the context of the current user, with a changed scope (S:C) indicating potential impact beyond the application itself. Adobe has addressed this in versions 23.0.16 and 24.0.14.
Affected products
- Adobe Animate 2023 <= 23.0.15
- Adobe Animate 2024 <= 24.0.13
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory