CVE-2021-42269: Adobe Animate FLA File Parsing Use After Free Remote Code Execution
Published Nov 18, 2021
·Updated
Adobe Animate version 21.0.9 (and earlier) are affected by a use-after-free vulnerability in the processing of a malformed FLA file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Adobe Animate<=21.0.9
Event History
Nov 18, 2021
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Animate vulnerability?
The vulnerability ID for this Adobe Animate vulnerability is CVE-2021-42269.
2
What is the severity of CVE-2021-42269?
The severity of CVE-2021-42269 is critical.
3
What is the affected version of Adobe Animate?
Adobe Animate version 21.0.9 (and earlier) is affected.
4
What is the impact of CVE-2021-42269?
CVE-2021-42269 could result in arbitrary code execution in the context of the current user.
5
How can CVE-2021-42269 be exploited?
Exploitation of this issue requires user interaction in that a victim must open a malicious FLA file.