First published: Wed Oct 21 2020(Updated: )
Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a crafted .fla file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Animate | <=20.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9747 is a vulnerability in Adobe Animate version 20.5 and earlier that allows for arbitrary code execution.
CVE-2020-9747 affects Adobe Animate version 20.5 and earlier by exploiting a double free vulnerability when parsing a crafted .fla file.
CVE-2020-9747 has a severity rating of 7.8 (Critical).
CVE-2020-9747 requires user interaction for exploitation.
No, Microsoft Windows is not vulnerable to CVE-2020-9747.
To fix CVE-2020-9747, users should update to a version of Adobe Animate that is not affected by the vulnerability.
More information about CVE-2020-9747 can be found on the Adobe security advisory page at: https://helpx.adobe.com/security/products/animate/apsb20-61.html
The CWE ID for CVE-2020-9747 is 415.