First published: Tue Aug 24 2021(Updated: )
Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Animate | <=21.0.6 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28618 is an Out-of-bounds Read vulnerability in Adobe Animate version 21.0.6 and earlier, which allows an attacker to disclose sensitive memory information.
An attacker can exploit CVE-2021-28618 by parsing a specially crafted file, which triggers the vulnerability and allows them to access sensitive memory information.
The severity of CVE-2021-28618 is considered medium, with a severity value of 5.5.
Adobe Animate version 21.0.6 and earlier are affected by CVE-2021-28618.
To mitigate CVE-2021-28618, it is recommended to update Adobe Animate to the latest version available.