CVE-2021-21076: Adobe Animate out-of-bounds read vulnerability
Published Mar 12, 2021
·Updated
Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Adobe Animate<=21.0.3
Microsoft Windows
Remediation
Event History
Mar 12, 2021
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21076?
The severity of CVE-2021-21076 is high with a CVSS score of 7.1.
2
How does CVE-2021-21076 affect Adobe Animate?
CVE-2021-21076 affects Adobe Animate version 21.0.3 (and earlier) by exposing an Out-of-bounds Read vulnerability.
3
Can an attacker exploit CVE-2021-21076 without authentication?
Yes, an unauthenticated attacker can exploit CVE-2021-21076.
4
What can an attacker do with CVE-2021-21076?
An attacker can leverage CVE-2021-21076 to disclose sensitive information in the context of the current user.
5
How can I fix CVE-2021-21076 in Adobe Animate?
To fix CVE-2021-21076, update Adobe Animate to version 21.0.4 or later.