CVE-2021-40733: Adobe Animate Memory Corruption Could Lead To Arbitrary Code Execution
Published Nov 18, 2021
·Updated
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected Software
2 affected components
Adobe Animate<=21.0.9
Microsoft Windows
Remediation
Event History
Nov 18, 2021
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Animate vulnerability?
The vulnerability ID for this Adobe Animate vulnerability is CVE-2021-40733.
2
What is the severity of CVE-2021-40733?
The severity of CVE-2021-40733 is critical with a CVSS score of 7.8.
3
Which version of Adobe Animate is affected by CVE-2021-40733?
Adobe Animate version 21.0.9 and earlier are affected by CVE-2021-40733.
4
What is the impact of CVE-2021-40733?
CVE-2021-40733 allows arbitrary code execution in the context of the current user, but user interaction is required to exploit the vulnerability.
5
How can I fix CVE-2021-40733?
To fix CVE-2021-40733, update Adobe Animate to version 21.1 or later as recommended by Adobe.