Executive brief
Adobe Animate, a professional animation and multimedia authoring software, is affected by a security flaw that could allow an attacker to take control of a user's computer. By tricking a user into opening a specially crafted malicious file, an attacker can bypass security restrictions to access sensitive data or run unauthorized commands. This could lead to a total compromise of the user's workstation and the data stored on it.
Technical details
A path traversal vulnerability (CWE-22) exists in Adobe Animate due to improper limitation of pathnames to restricted directories. The flaw is triggered when the application processes a maliciously crafted file, requiring user interaction (UI:R). Successful exploitation allows an attacker to escape the intended directory structure, potentially leading to arbitrary code execution in the context of the current user. The vulnerability has a 'Changed' scope (S:C), indicating it can impact components beyond the immediate software environment. Patches are available in versions 23.0.16 and 24.0.14.
Affected products
- Adobe Animate 2023 <= 23.0.15
- Adobe Animate 2024 <= 24.0.13
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory