CVE-2021-42267: Adobe Animate FLA File Parsing Memory Corruption Arbitrary Code Execution
Published Nov 18, 2021
·Updated
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected Software
1 affected component
Adobe Animate<=21.0.9
Event History
Nov 18, 2021
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Animate vulnerability?
The vulnerability ID for this Adobe Animate vulnerability is CVE-2021-42267.
2
What is the severity of CVE-2021-42267?
The severity of CVE-2021-42267 is critical, with a CVSS score of 7.8.
3
Which version of Adobe Animate is affected by CVE-2021-42267?
Adobe Animate version 21.0.9 (and earlier) is affected by CVE-2021-42267.
4
What is the cause of CVE-2021-42267?
CVE-2021-42267 is caused by insecure handling of a malicious FLA file in Adobe Animate.
5
Is user interaction required to exploit CVE-2021-42267?
Yes, user interaction is required to exploit CVE-2021-42267.