CVE-2021-28618: Adobe Animate out-of-bounds read vulnerability could lead to sensitive information disclosure
Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-28618?
CVE-2021-28618 is an Out-of-bounds Read vulnerability in Adobe Animate version 21.0.6 and earlier, which allows an attacker to disclose sensitive memory information.
How can an attacker exploit CVE-2021-28618?
An attacker can exploit CVE-2021-28618 by parsing a specially crafted file, which triggers the vulnerability and allows them to access sensitive memory information.
What is the severity of CVE-2021-28618?
The severity of CVE-2021-28618 is considered medium, with a severity value of 5.5.
Which version of Adobe Animate is affected by CVE-2021-28618?
Adobe Animate version 21.0.6 and earlier are affected by CVE-2021-28618.
How do I mitigate the vulnerability CVE-2021-28618?
To mitigate CVE-2021-28618, it is recommended to update Adobe Animate to the latest version available.