Executive brief
Adobe Animate, a professional animation and multimedia authoring tool, is affected by a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands and gain the same level of access as the current user, potentially leading to data theft or system compromise.
Technical details
Adobe Animate (versions 2023 and 2024) contains an OS Command Injection vulnerability (CWE-78) due to improper neutralization of special elements. The vulnerability is triggered when the application processes a maliciously crafted file, requiring user interaction. Successful exploitation allows for arbitrary code execution in the context of the current user. The CVSS score reflects a changed scope (S:C), indicating the impact can extend beyond the Animate application to the underlying operating system. Adobe has released patches in versions 23.0.16 and 24.0.14 to address this issue.
Affected products
- Adobe Animate 2023 <= 23.0.15
- Adobe Animate 2024 <= 24.0.13
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-07-14: patched