CVE-2021-42268: Adobe Animate FLA File Parsing Null Pointer Dereference Application Denial of Service
Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted FLA file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Animate vulnerability?
The vulnerability ID for this Adobe Animate vulnerability is CVE-2021-42268.
What is the severity rating of CVE-2021-42268?
CVE-2021-42268 has a severity rating of 5.5 (medium).
What is the affected software version of CVE-2021-42268?
Adobe Animate version 21.0.9 (and earlier) is affected by CVE-2021-42268.
What is the impact of CVE-2021-42268?
CVE-2021-42268 allows an unauthenticated attacker to achieve an application denial-of-service in the context of the current user.
Is there a fix available for CVE-2021-42268?
Yes, Adobe has released a security update to address CVE-2021-42268. It is recommended to update to the latest version of Adobe Animate.